<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to remove DateParserVerbose component Error messages? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-DateParserVerbose-component-Error-messages/m-p/310653#M96024</link>
    <description>&lt;P&gt;What Sourcetype are you using for the following hosts/sources?&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;c:\inetpub\wwwroot\sf-api\logs\v3API.txt|host::SFUTIL1-TEST&lt;/CODE&gt;&lt;BR /&gt;
&lt;CODE&gt;D:\sc\logs\StorageCenterLog_20170405.log|host::storage-usw-85&lt;/CODE&gt;&lt;BR /&gt;
&lt;CODE&gt;D:\sc\logs\StorageCenterLog_20170405.log|host::storage-usw-83&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Can you share the props.conf for those sourcetypes?&lt;/P&gt;

&lt;P&gt;It looks like there could be an opportunity to improve timestamp recognition settings in props.conf ie. &lt;CODE&gt;TIME_PREFIX&lt;/CODE&gt;, &lt;CODE&gt;TIME_FORMAT&lt;/CODE&gt;, &lt;CODE&gt;MAX_TIMESTAMP_LOOKAHEAD&lt;/CODE&gt;to improve timestamping. &lt;/P&gt;

&lt;P&gt;There are times when ignoring these messages may be required, if the data you are ingesting is void of timestamps or has strange formatting. But let's start by ensuring your sourcetype has been configured optimally. Add data wizard on a dev machine can make this much easier as well. &lt;/P&gt;</description>
    <pubDate>Sat, 08 Apr 2017 14:03:06 GMT</pubDate>
    <dc:creator>mattymo</dc:creator>
    <dc:date>2017-04-08T14:03:06Z</dc:date>
    <item>
      <title>How to remove DateParserVerbose component Error messages?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-DateParserVerbose-component-Error-messages/m-p/310652#M96023</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We are getting below mentioned Error and Warning messages in HealthOverviewApp on our cloud instance, &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Failed to parse timestamp. Defaulting to timestamp of previous event (Wed Apr 5 05:16:59 2017). Context: source::c:\inetpub\wwwroot\sf-api\logs\v3API.txt|host::SFUTIL1-TEST|breakable_text|554\n 3 similar messages suppressed. First occurred at: Wed Apr 5 05:17:00 2017&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Accepted time (Wed Apr 5 05:21:54 2017) is suspiciously far away from the previous event's time (Thu Mar 2 00:59:24 2017), but still accepted because it was extracted by the same pattern. Context: source::D:\sc\logs\StorageCenterLog_20170405.log|host::storage-usw-85|StorageCenter-production|333959&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Time parsed (Thu Mar 16 19:16:44 2017) is too far away from the previous event's time (Wed Apr 5 05:17:22 2017) to be accepted. If this is a correct time, MAX_DIFF_SECS_AGO (3600) or MAX_DIFF_SECS_HENCE (604800) may be overly restrictive. Context: source::D:\sc\logs\StorageCenterLog_20170405.log|host::storage-usw-83|StorageCenter-production|332108&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Can anyone suggest a solution for getting these errors removed?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:32:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-DateParserVerbose-component-Error-messages/m-p/310652#M96023</guid>
      <dc:creator>arpit_1210</dc:creator>
      <dc:date>2020-09-29T13:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove DateParserVerbose component Error messages?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-DateParserVerbose-component-Error-messages/m-p/310653#M96024</link>
      <description>&lt;P&gt;What Sourcetype are you using for the following hosts/sources?&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;c:\inetpub\wwwroot\sf-api\logs\v3API.txt|host::SFUTIL1-TEST&lt;/CODE&gt;&lt;BR /&gt;
&lt;CODE&gt;D:\sc\logs\StorageCenterLog_20170405.log|host::storage-usw-85&lt;/CODE&gt;&lt;BR /&gt;
&lt;CODE&gt;D:\sc\logs\StorageCenterLog_20170405.log|host::storage-usw-83&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Can you share the props.conf for those sourcetypes?&lt;/P&gt;

&lt;P&gt;It looks like there could be an opportunity to improve timestamp recognition settings in props.conf ie. &lt;CODE&gt;TIME_PREFIX&lt;/CODE&gt;, &lt;CODE&gt;TIME_FORMAT&lt;/CODE&gt;, &lt;CODE&gt;MAX_TIMESTAMP_LOOKAHEAD&lt;/CODE&gt;to improve timestamping. &lt;/P&gt;

&lt;P&gt;There are times when ignoring these messages may be required, if the data you are ingesting is void of timestamps or has strange formatting. But let's start by ensuring your sourcetype has been configured optimally. Add data wizard on a dev machine can make this much easier as well. &lt;/P&gt;</description>
      <pubDate>Sat, 08 Apr 2017 14:03:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-DateParserVerbose-component-Error-messages/m-p/310653#M96024</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2017-04-08T14:03:06Z</dc:date>
    </item>
  </channel>
</rss>

