<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DEBUG AggregatorMiningProcessor - Failed to parse timestamp getting this message in splunkd.log in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211104#M96221</link>
    <description>&lt;P&gt;Hey Hemnaath,&lt;/P&gt;

&lt;P&gt;Splunk is just advising you that it cannot auto parse your timestamp in your bluecoat logs and is differing to the sourcetype set for that input.&lt;/P&gt;

&lt;P&gt;what does your bluecoat props.conf look like?&lt;/P&gt;</description>
    <pubDate>Sun, 06 Nov 2016 16:59:27 GMT</pubDate>
    <dc:creator>mattymo</dc:creator>
    <dc:date>2016-11-06T16:59:27Z</dc:date>
    <item>
      <title>DEBUG AggregatorMiningProcessor - Failed to parse timestamp getting this message in splunkd.log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211103#M96220</link>
      <description>&lt;P&gt;Hi All, I could this message into my Heavy Forwarder instance (Splunkd.log) I am not sure what is the problem why I am getting this information in my splunkd.log.  We are using Splunk 6.2.1 version and its running in Linux 64 bit instance VM machine. Kindly guide me on how to fix this issue, as I am very much beginner in splunk.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;splunkd.log&lt;/STRONG&gt;&lt;BR /&gt;
11-06-2016 10:58:38.108 -0500 DEBUG AggregatorMiningProcessor - Failed to parse timestamp. Defaulting to time specified by data input. - data_source="/opt/syslogs/proxy/uspxxxx.xxxx.com/bluecoat.log", data_host="uspxxxx.xxxx.com", data_sourcetype="bluecoat_syslog"&lt;BR /&gt;
11-06-2016 10:58:38.109 -0500 DEBUG AggregatorMiningProcessor - Failed to parse timestamp. Defaulting to time specified by data input. - data_source="/opt/syslogs/proxy/uspxxxx.xxxx.com/bluecoat.log", data_host="uspxxxx.xxxx.com", data_sourcetype="bluecoat_syslog"&lt;BR /&gt;
11-06-2016 10:58:38.109 -0500 DEBUG AggregatorMiningProcessor - Failed to parse timestamp. Defaulting to time specified by data input. - data_source="/opt/syslogs/proxy/uspxxxx.xxxx.com/bluecoat.log", data_host="uspxxxx.xxxx.com", data_sourcetype="bluecoat_syslog"&lt;BR /&gt;
11-06-2016 10:58:38.109 -0500 DEBUG AggregatorMiningProcessor - Failed to parse timestamp. Defaulting to time specified by data input. - data_source="/opt/syslogs/proxy/uspxxxx.xxxx.com/bluecoat.log", data_host="uspxxxx.xxxx.com", data_sourcetype="bluecoat_syslog"&lt;BR /&gt;
11-06-2016 10:58:38.109 -0500 DEBUG AggregatorMiningProcessor - Failed to parse timestamp. Defaulting to time specified by data input. - data_source="/opt/syslogs/proxy/uspxxxx.xxxx.com/bluecoat.log", data_host="uspxxxx.xxxx.com", data_sourcetype="bluecoat_syslog"&lt;/P&gt;

&lt;P&gt;thanks in advance. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:41:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211103#M96220</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2020-09-29T11:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: DEBUG AggregatorMiningProcessor - Failed to parse timestamp getting this message in splunkd.log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211104#M96221</link>
      <description>&lt;P&gt;Hey Hemnaath,&lt;/P&gt;

&lt;P&gt;Splunk is just advising you that it cannot auto parse your timestamp in your bluecoat logs and is differing to the sourcetype set for that input.&lt;/P&gt;

&lt;P&gt;what does your bluecoat props.conf look like?&lt;/P&gt;</description>
      <pubDate>Sun, 06 Nov 2016 16:59:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211104#M96221</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2016-11-06T16:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: DEBUG AggregatorMiningProcessor - Failed to parse timestamp getting this message in splunkd.log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211105#M96222</link>
      <description>&lt;P&gt;thanks mmodestino for your quick response on this.  I could see two props.conf file for bluecoat_syslog.  One is  under the app name called TA-Bluecoat and Another app name Admin-HVY-Forwarder.&lt;/P&gt;

&lt;P&gt;Under TA-Bluecoat app I do not see any inputs.conf file defined, whereas under Admin-HVY-Forwarder could see inputs.conf defined but props.conf is not defined for bluecoat.&lt;/P&gt;

&lt;P&gt;App name &lt;STRONG&gt;Admin-HVY-Forwarder&lt;/STRONG&gt; - Props.conf&lt;BR /&gt;
[host::Tesx*]&lt;BR /&gt;
TZ = GMT&lt;/P&gt;

&lt;P&gt;[host::TESX*]&lt;BR /&gt;
TZ = GMT&lt;/P&gt;

&lt;P&gt;[f5_web_server]&lt;BR /&gt;
TIME_PREFIX = f5_time="&lt;BR /&gt;
TRANSFORM-time = f5_syslog_time&lt;/P&gt;

&lt;P&gt;Under &lt;STRONG&gt;app name TA-bluecoat&lt;/STRONG&gt;, could see this configuration setup&lt;BR /&gt;
Props.conf detail&lt;BR /&gt;
[source::....bluecoat]&lt;BR /&gt;
sourcetype = bluecoat&lt;/P&gt;

&lt;P&gt;[bluecoat]&lt;BR /&gt;
SHOULD_LINEMERGE=false&lt;BR /&gt;
KV_MODE = none&lt;BR /&gt;
REPORT-0auto_kv_for_bluecoat = auto_kv_for_bluecoat&lt;BR /&gt;
LOOKUP-vendor_info_for_bluecoat = bluecoat_vendor_info_lookup sourcetype OUTPUT vendor,product&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD = 19&lt;BR /&gt;
TIME_FORMAT = %Y-%m-%d %T&lt;BR /&gt;
TRANSFORM-main = nullPound&lt;BR /&gt;
TRANSFORMS-bluecoat_host_override = bluecoat_host_override&lt;BR /&gt;
TZ = GMT&lt;/P&gt;

&lt;P&gt;[bluecoat_syslog]&lt;BR /&gt;
SHOULD_LINEMERGE=false&lt;BR /&gt;
KV_MODE = none&lt;BR /&gt;
REPORT-0auto_kv_for_bluecoat = auto_kv_for_bluecoat_syslog&lt;BR /&gt;
LOOKUP-vendor_info_for_bluecoat = bluecoat_vendor_info_lookup sourcetype OUTPUT vendor,product&lt;BR /&gt;
TIME_PREFIX = \w{3}\s\d{1,2}\s\d{1,2}:\d{1,2}:\d{1,2}\s\w+.\w+.\w+.&lt;BR /&gt;
TIME_FORMAT = %Y-%m-%d %H:%M:%S&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD = 19&lt;BR /&gt;
TRANSFORM-main = nullPound&lt;BR /&gt;
TRANSFORMS-bluecoat_host_override = bluecoat_host_override&lt;/P&gt;

&lt;P&gt;thanks in advance. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:41:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211105#M96222</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2020-09-29T11:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: DEBUG AggregatorMiningProcessor - Failed to parse timestamp getting this message in splunkd.log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211106#M96223</link>
      <description>&lt;P&gt;looks like ur all good! This is just a debug message telling you how splunk is setting the timestamp. &lt;/P&gt;

&lt;P&gt;Are you running debug log level?&lt;/P&gt;</description>
      <pubDate>Sun, 06 Nov 2016 18:11:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211106#M96223</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2016-11-06T18:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: DEBUG AggregatorMiningProcessor - Failed to parse timestamp getting this message in splunkd.log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211107#M96224</link>
      <description>&lt;P&gt;thanks mmodestino, but how to figure out whether we are running the debug log level in splunk ?&lt;/P&gt;</description>
      <pubDate>Sun, 06 Nov 2016 18:14:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211107#M96224</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2016-11-06T18:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: DEBUG AggregatorMiningProcessor - Failed to parse timestamp getting this message in splunkd.log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211108#M96225</link>
      <description>&lt;P&gt;You likely arent...what does your inputs.conf look like for this heavy forwarder?&lt;/P&gt;</description>
      <pubDate>Sun, 06 Nov 2016 18:47:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211108#M96225</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2016-11-06T18:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: DEBUG AggregatorMiningProcessor - Failed to parse timestamp getting this message in splunkd.log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211109#M96226</link>
      <description>&lt;P&gt;Taken only particular stanza related to bluecoat_syslogs from Admin-HVY-forwarder app&lt;/P&gt;

&lt;P&gt;/opt/splunk/etc/apps/Admin-HVY-forwarder/default&lt;/P&gt;

&lt;P&gt;[monitor:///opt/syslogs/proxy/.../*bluecoat.log]&lt;BR /&gt;
whitelist = .log$&lt;BR /&gt;
sourcetype = bluecoat_syslog&lt;BR /&gt;
index = net_proxy&lt;BR /&gt;
host_segment = 4&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:41:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211109#M96226</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2020-09-29T11:41:10Z</dc:date>
    </item>
    <item>
      <title>Re: DEBUG AggregatorMiningProcessor - Failed to parse timestamp getting this message in splunkd.log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211110#M96227</link>
      <description>&lt;P&gt;you set up looks fine to me...I am pretty sure these messages can be disregarded as they are simply verbose debug logs. Your timestamping is working correctly, right?&lt;/P&gt;</description>
      <pubDate>Sun, 06 Nov 2016 19:56:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211110#M96227</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2016-11-06T19:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: DEBUG AggregatorMiningProcessor - Failed to parse timestamp getting this message in splunkd.log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211111#M96228</link>
      <description>&lt;P&gt;thanks mmodestino for throwing some lights on this issue.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 12:33:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DEBUG-AggregatorMiningProcessor-Failed-to-parse-timestamp/m-p/211111#M96228</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2016-11-07T12:33:51Z</dc:date>
    </item>
  </channel>
</rss>

