<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HELP with CEF CSV time format in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/HELP-with-CEF-CSV-time-format/m-p/676176#M9860</link>
    <description>&lt;P&gt;I am new to splunk and I have inherited a system that forwards log in CEF CSV format.&amp;nbsp; These logs are then tar'd up and sent to the distant end (which does happen successfully).&amp;nbsp; The issue I have is when the splunk server picks up the CEF CSV it has epoch time as the first entry of every log in the CEF CSV file.&amp;nbsp; This makes the next hop/stop aggregator I send to unhappy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;original host (forwarder) -&amp;gt; splunk host -&amp;gt; splunk host -&amp;gt; master aggregator (arcsight type server)&lt;/P&gt;&lt;P&gt;example:&lt;/P&gt;&lt;P&gt;1706735561, "blah blah blah"&lt;/P&gt;&lt;P&gt;the file cef.csv says it's doing "_time","_raw"&lt;/P&gt;&lt;P&gt;When I look at what I think is the setup for time (etc/datetime.xml), _time does not have anything about epoch or %s in there.&lt;/P&gt;&lt;P&gt;How do I configure the CEF CSV to omit the epoch time?&lt;/P&gt;&lt;P&gt;As I mentioned earlier, I am totally new to splunk.&amp;nbsp; Any help would be fantastic.&lt;/P&gt;</description>
    <pubDate>Wed, 31 Jan 2024 22:06:00 GMT</pubDate>
    <dc:creator>yhetti</dc:creator>
    <dc:date>2024-01-31T22:06:00Z</dc:date>
    <item>
      <title>HELP with CEF CSV time format</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/HELP-with-CEF-CSV-time-format/m-p/676176#M9860</link>
      <description>&lt;P&gt;I am new to splunk and I have inherited a system that forwards log in CEF CSV format.&amp;nbsp; These logs are then tar'd up and sent to the distant end (which does happen successfully).&amp;nbsp; The issue I have is when the splunk server picks up the CEF CSV it has epoch time as the first entry of every log in the CEF CSV file.&amp;nbsp; This makes the next hop/stop aggregator I send to unhappy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;original host (forwarder) -&amp;gt; splunk host -&amp;gt; splunk host -&amp;gt; master aggregator (arcsight type server)&lt;/P&gt;&lt;P&gt;example:&lt;/P&gt;&lt;P&gt;1706735561, "blah blah blah"&lt;/P&gt;&lt;P&gt;the file cef.csv says it's doing "_time","_raw"&lt;/P&gt;&lt;P&gt;When I look at what I think is the setup for time (etc/datetime.xml), _time does not have anything about epoch or %s in there.&lt;/P&gt;&lt;P&gt;How do I configure the CEF CSV to omit the epoch time?&lt;/P&gt;&lt;P&gt;As I mentioned earlier, I am totally new to splunk.&amp;nbsp; Any help would be fantastic.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 22:06:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/HELP-with-CEF-CSV-time-format/m-p/676176#M9860</guid>
      <dc:creator>yhetti</dc:creator>
      <dc:date>2024-01-31T22:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: HELP with CEF CSV time format</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/HELP-with-CEF-CSV-time-format/m-p/676203#M9861</link>
      <description>&lt;P&gt;1. Do you use indexed extractions or not?&lt;/P&gt;&lt;P&gt;2. Do you have time extraction properly configured (TIME_PREFIX, TIME_FORMAT, MAX_TIMESTAMP_LOOKAHEAD)?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2024 07:36:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/HELP-with-CEF-CSV-time-format/m-p/676203#M9861</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-02-01T07:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: HELP with CEF CSV time format</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/HELP-with-CEF-CSV-time-format/m-p/677218#M9873</link>
      <description>&lt;P&gt;Thank You for replying:&lt;/P&gt;&lt;P&gt;I am totally new to this so I don't have the domain knowledge.&lt;/P&gt;&lt;P&gt;I believe it is indexed extractions.&lt;/P&gt;&lt;P&gt;As far as the extraction configuration it shows _time, _raw&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;again I am a total noob - I appreciate any assistance.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Feb 2024 19:50:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/HELP-with-CEF-CSV-time-format/m-p/677218#M9873</guid>
      <dc:creator>yhetti</dc:creator>
      <dc:date>2024-02-10T19:50:47Z</dc:date>
    </item>
  </channel>
</rss>

