<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: subseconds forwarded via LightForwarder not recognized in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/subseconds-forwarded-via-LightForwarder-not-recognized/m-p/24591#M96610</link>
    <description>&lt;P&gt;Have you tried setting the time format for that sourcetype explicitly in props.conf?  I think the TIME_FORMAT would be %m/%d/%y %H:%M:%S,%3N&lt;/P&gt;

&lt;P&gt;Not sure, but there may be a difference in how Splunk examines your data when coming via lightforwarder, and the props.conf setting should force the same behavior.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Dec 2010 22:49:23 GMT</pubDate>
    <dc:creator>jhedgpeth</dc:creator>
    <dc:date>2010-12-21T22:49:23Z</dc:date>
    <item>
      <title>subseconds forwarded via LightForwarder not recognized</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/subseconds-forwarded-via-LightForwarder-not-recognized/m-p/24588#M96607</link>
      <description>&lt;P&gt;I have a log event with a timestamp that includes milliseconds:
2010-07-30 11:16:43,357 &lt;/P&gt;

&lt;P&gt;If the log is loaded into Splunk on the indexer the subseconds get recognized.&lt;/P&gt;

&lt;P&gt;If the log is forwarded via LightForwarder, subseconds are not recognized:&lt;/P&gt;

&lt;P&gt;7/30/10 11:16:43,000 AM&lt;/P&gt;

&lt;P&gt;How can I correct this? &lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2010 22:43:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/subseconds-forwarded-via-LightForwarder-not-recognized/m-p/24588#M96607</guid>
      <dc:creator>Jaci</dc:creator>
      <dc:date>2010-08-03T22:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: subseconds forwarded via LightForwarder not recognized</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/subseconds-forwarded-via-LightForwarder-not-recognized/m-p/24589#M96608</link>
      <description>&lt;P&gt;Is this the case for all data or just from this source? I've tested a 4.1.x instance with the logs in index=_internal and subseconds are correctly parsed and rendered. Are there custom timestamping rules on the forwarder?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2010 04:57:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/subseconds-forwarded-via-LightForwarder-not-recognized/m-p/24589#M96608</guid>
      <dc:creator>Stephen_Sorkin</dc:creator>
      <dc:date>2010-08-18T04:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: subseconds forwarded via LightForwarder not recognized</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/subseconds-forwarded-via-LightForwarder-not-recognized/m-p/24590#M96609</link>
      <description>&lt;P&gt;We are sure there are no other rules on the LightForwarder. We also deleted all files under .../apps/learned and .../etc/users.&lt;/P&gt;

&lt;P&gt;Subseconds still are not recognized from ALL sources.&lt;/P&gt;

&lt;P&gt;Any more ideas how to debug / loglevel to make timestamp recognition visible ?&lt;/P&gt;

&lt;P&gt;Thanks for helping,
Meno&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2010 13:06:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/subseconds-forwarded-via-LightForwarder-not-recognized/m-p/24590#M96609</guid>
      <dc:creator>meno</dc:creator>
      <dc:date>2010-08-24T13:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: subseconds forwarded via LightForwarder not recognized</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/subseconds-forwarded-via-LightForwarder-not-recognized/m-p/24591#M96610</link>
      <description>&lt;P&gt;Have you tried setting the time format for that sourcetype explicitly in props.conf?  I think the TIME_FORMAT would be %m/%d/%y %H:%M:%S,%3N&lt;/P&gt;

&lt;P&gt;Not sure, but there may be a difference in how Splunk examines your data when coming via lightforwarder, and the props.conf setting should force the same behavior.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2010 22:49:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/subseconds-forwarded-via-LightForwarder-not-recognized/m-p/24591#M96610</guid>
      <dc:creator>jhedgpeth</dc:creator>
      <dc:date>2010-12-21T22:49:23Z</dc:date>
    </item>
  </channel>
</rss>

