<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk time parse in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-time-parse/m-p/673255#M11862</link>
    <description>&lt;P&gt;If&lt;/P&gt;&lt;PRE&gt;ADD_EXTRA_TIME_FIELDS = true&lt;/PRE&gt;&lt;P&gt;then why wouldn't t&lt;SPAN&gt;hose fields be present in every event?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How could we ensure that those fields are present in every event?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jan 2024 17:38:46 GMT</pubDate>
    <dc:creator>landen99</dc:creator>
    <dc:date>2024-01-04T17:38:46Z</dc:date>
    <item>
      <title>Splunk time parse</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-time-parse/m-p/665828#M11755</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk usually takes the log time event (_time) and parse it to:&lt;/P&gt;&lt;P&gt;date_hour,&amp;nbsp;date_mday,&amp;nbsp;date_minute,&amp;nbsp;date_month,&amp;nbsp;date_second,&amp;nbsp;date_wday, date_year&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screenshot 2023-10-23 121840.png" style="width: 487px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27700i044C41BD92674EDB/image-dimensions/487x278?v=v2" width="487" height="278" role="button" title="Screenshot 2023-10-23 121840.png" alt="Screenshot 2023-10-23 121840.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have found that some of our indexes does not contain this parse only the _time field.&lt;/P&gt;&lt;P&gt;What may cause this issue?&lt;/P&gt;&lt;P&gt;In addition, I am not sure but I have found something related to "DATETIME_CONFIG = /etc/datetime.xml" might be a good point not much on the internet that explain pretty well how to resolve this.&lt;/P&gt;&lt;P&gt;Would appreciate&amp;nbsp;your help here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 09:21:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-time-parse/m-p/665828#M11755</guid>
      <dc:creator>Eyal</dc:creator>
      <dc:date>2023-10-23T09:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk time parse</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-time-parse/m-p/665843#M11758</link>
      <description>&lt;P&gt;This is defined in props.conf for the sourcetype, see the&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;ADD_EXTRA_TIME_FIELDS&lt;/PRE&gt;&lt;P&gt;setting in this documentation&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf#Timestamp_extraction_configuration" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf#Timestamp_extraction_configuration&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 12:39:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-time-parse/m-p/665843#M11758</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-10-23T12:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk time parse</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-time-parse/m-p/665847#M11759</link>
      <description>&lt;P&gt;Those fields are not present in every event.&amp;nbsp; See &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Usedefaultfields" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Usedefaultfields&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 12:51:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-time-parse/m-p/665847#M11759</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-10-23T12:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk time parse</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-time-parse/m-p/673255#M11862</link>
      <description>&lt;P&gt;If&lt;/P&gt;&lt;PRE&gt;ADD_EXTRA_TIME_FIELDS = true&lt;/PRE&gt;&lt;P&gt;then why wouldn't t&lt;SPAN&gt;hose fields be present in every event?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How could we ensure that those fields are present in every event?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 17:38:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-time-parse/m-p/673255#M11862</guid>
      <dc:creator>landen99</dc:creator>
      <dc:date>2024-01-04T17:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk time parse</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-time-parse/m-p/673269#M11863</link>
      <description>&lt;P&gt;An event that does not have a timestamp will not have date_* fields.&amp;nbsp; That includes events where &lt;FONT face="courier new,courier"&gt;DATETIME_CONFIG=current&lt;/FONT&gt; or &lt;FONT face="courier new,courier"&gt;DATETIME_CONFIG=none&lt;/FONT&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 19:33:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-time-parse/m-p/673269#M11863</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-01-04T19:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk time parse</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-time-parse/m-p/673333#M11867</link>
      <description>&lt;P&gt;Adding to what has already been said - I would advise _against_ using those fields.&lt;/P&gt;&lt;P&gt;Their contents may be misleading, especially if you ingest data from different timezones and searching by them can be additionally skewed vs. what you expect if you're yet in another timezone.&lt;/P&gt;&lt;P&gt;Quoting the docs:&lt;/P&gt;&lt;P&gt;[...]&lt;/P&gt;&lt;P&gt;If an event has a date_* field, it represents the value of time/date directly from the event itself. If you have specified any timezone conversions or changed the value of the time/date at indexing or input time (for example, by setting the timestamp to be the time at index or input time), these fields will not represent that.&lt;/P&gt;&lt;P&gt;[...]&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 10:49:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-time-parse/m-p/673333#M11867</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-01-05T10:49:03Z</dc:date>
    </item>
  </channel>
</rss>

