<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: There are 2 timestamp formats in a log file in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535799#M151447</link>
    <description>&lt;P&gt;Thanks a &lt;A href="mailto:lot@to4kawa" target="_blank"&gt;lot. @to4kawa&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I try to run your spl statement, and the result is only 3 events, but I have more than 3 events. Can I provide the configuration props.conf file to extract the timestamp when uploading new data?&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jan 2021 09:42:24 GMT</pubDate>
    <dc:creator>lish123</dc:creator>
    <dc:date>2021-01-14T09:42:24Z</dc:date>
    <item>
      <title>There are 2 timestamp formats in a log file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535624#M151393</link>
      <description>&lt;P&gt;&amp;lt;Jan 10, 2021 6:58:06 PM CST&amp;gt; &amp;lt;Info&amp;gt; &amp;lt;WorkManager&amp;gt; &amp;lt;BEA-002942&amp;gt; &amp;lt;CMM memory level becomes 0. Setting standby thread pool size to 256.&amp;gt;&lt;BR /&gt;&amp;lt;Jan 10, 2021 6:58:06,538 PM CST&amp;gt; &amp;lt;Notice&amp;gt; &amp;lt;Log Management&amp;gt; &amp;lt;BEA-170019&amp;gt; &amp;lt;The server log file weblogic.logging.FileStreamHandler instance=1128635794&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 09:43:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535624#M151393</guid>
      <dc:creator>lish123</dc:creator>
      <dc:date>2021-01-13T09:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: There are 2 timestamp formats in a log file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535633#M151396</link>
      <description>&lt;P&gt;What is your requirement ? are you looking for ingesting these 2 events in splunk with 2 time format ?&amp;nbsp;&lt;BR /&gt;or you are looking to make constant time format for an all event when ingested to splunk .&lt;/P&gt;&lt;P&gt;I can try to provide solution once requirement are specified.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Meanwhile for both type of question you will get answer in example of below &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.1/Data/Configuretimestamprecognition" target="_self"&gt;documentation&lt;/A&gt;.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 11:15:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535633#M151396</guid>
      <dc:creator>askkawalkar</dc:creator>
      <dc:date>2021-01-13T11:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: There are 2 timestamp formats in a log file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535635#M151397</link>
      <description>&lt;P&gt;Check in props.conf and adjust timezone settings with "TZ" for your sourcetype&lt;/P&gt;&lt;P&gt;Example&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[your sourcetype]
TZ = GMT&lt;/LI-CODE&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Archive/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306839" target="_blank"&gt;https://community.splunk.com/t5/Archive/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306839&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 11:22:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535635#M151397</guid>
      <dc:creator>General_Talos</dc:creator>
      <dc:date>2021-01-13T11:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: There are 2 timestamp formats in a log file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535743#M151421</link>
      <description>&lt;P&gt;It’s not a time zone issue. One event contains milliseconds and the other does not contain milliseconds.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 01:40:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535743#M151421</guid>
      <dc:creator>lish123</dc:creator>
      <dc:date>2021-01-14T01:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: There are 2 timestamp formats in a log file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535746#M151423</link>
      <description>&lt;P&gt;I want to extract these 2 events in a timestamp format.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 01:43:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535746#M151423</guid>
      <dc:creator>lish123</dc:creator>
      <dc:date>2021-01-14T01:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: There are 2 timestamp formats in a log file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535763#M151434</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213196"&gt;@lish123&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Please place below parameters in props.conf, replace SOURCETYPENAME with actual sourcetype.&amp;nbsp; If you are aware about regex, you can define your own regex&lt;/P&gt;&lt;LI-CODE lang="python"&gt;[SOURCETYPENAME]
SHOULD_LINEMERGE = false
LINE_BREAKER = ([\r\n]+)
TIME_PREFIX = \&amp;lt;(?&amp;lt;Time&amp;gt;\w{3} \d{1,2}, \d{4} \d{1,2}:\d{2}:\d{2}[,\d{3}]* PM CST)\&amp;gt;
TIME_FORMAT = %b %d, %Y %I:%M:%S,%Q %p %Z&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 06:17:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535763#M151434</guid>
      <dc:creator>askkawalkar</dc:creator>
      <dc:date>2021-01-14T06:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: There are 2 timestamp formats in a log file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535768#M151436</link>
      <description>&lt;P&gt;Thanks a lot &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/148093"&gt;@askkawalkar&lt;/a&gt;&lt;/P&gt;&lt;P&gt;However, this TIME_FORMAT&lt;/P&gt;&lt;P&gt;%B%d,%Y%I:%M:%S,%Q%p%Z&lt;BR /&gt;Cannot extract this type of timestamp correctly&lt;/P&gt;&lt;P&gt;&amp;lt;CST 6:58:06 PM, January 10, 2021&amp;gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 06:57:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535768#M151436</guid>
      <dc:creator>lish123</dc:creator>
      <dc:date>2021-01-14T06:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: There are 2 timestamp formats in a log file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535770#M151437</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213196"&gt;@lish123&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have developed solution based on timestamp in sample data you provided.&lt;/P&gt;&lt;P&gt;Is there any more types of timeformat in the log ?&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 07:07:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535770#M151437</guid>
      <dc:creator>askkawalkar</dc:creator>
      <dc:date>2021-01-14T07:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: There are 2 timestamp formats in a log file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535785#M151441</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=_internal | head 1 | fields _raw _time
| eval _raw="&amp;lt;Jan 10, 2021 6:58:06 PM CST&amp;gt; &amp;lt;Info&amp;gt; &amp;lt;WorkManager&amp;gt; &amp;lt;BEA-002942&amp;gt; &amp;lt;CMM memory level becomes 0. Setting standby thread pool size to 256.&amp;gt;
&amp;lt;Jan 10, 2021 6:58:06,538 PM CST&amp;gt; &amp;lt;Notice&amp;gt; &amp;lt;Log Management&amp;gt; &amp;lt;BEA-170019&amp;gt; &amp;lt;The server log file weblogic.logging.FileStreamHandler instance=1128635794
&amp;lt;CST 6:58:06 PM, January 10, 2021&amp;gt; &amp;lt;Notice&amp;gt; &amp;lt;Log Management&amp;gt; &amp;lt;BEA-170019&amp;gt; &amp;lt;The server log file weblogic.logging.FileStreamHandler instance=1128635794"
| multikv noheader=t
| fields - Col*

| rex "&amp;lt;(?P&amp;lt;time&amp;gt;.*?)&amp;gt;"
| eval _time=case(match(time,",\d{3}\s*[AP]M"),strptime(replace(time,"CST","-0600"),"%b %d, %Y %T,%3N %p %:z"),
match(time,"^[A-Z][a-z]+\b"),strptime(replace(time,"CST","-0600"),"%b %d, %Y %T %p %:z"),
match(time,"^CST+\b"),strptime(replace(time,"CST","-0600"),"%:z %T %p, %B %d, %Y"))&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How about INGEST_EVAL?&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.1/Data/IngestEval" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.1/Data/IngestEval&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 08:50:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535785#M151441</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2021-01-14T08:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: There are 2 timestamp formats in a log file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535799#M151447</link>
      <description>&lt;P&gt;Thanks a &lt;A href="mailto:lot@to4kawa" target="_blank"&gt;lot. @to4kawa&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I try to run your spl statement, and the result is only 3 events, but I have more than 3 events. Can I provide the configuration props.conf file to extract the timestamp when uploading new data?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 09:42:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535799#M151447</guid>
      <dc:creator>lish123</dc:creator>
      <dc:date>2021-01-14T09:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: There are 2 timestamp formats in a log file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535803#M151448</link>
      <description>&lt;P&gt;Set up transforms.conf as described in the reference.&lt;/P&gt;&lt;P&gt;First, extract the &lt;STRONG&gt;time&lt;/STRONG&gt; field with REGEX and then set INGEST_EVAL.&lt;BR /&gt;For eval, you can use the same one as in SPL.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 09:57:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/There-are-2-timestamp-formats-in-a-log-file/m-p/535803#M151448</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2021-01-14T09:57:08Z</dc:date>
    </item>
  </channel>
</rss>

