<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how to Configure positional timestamp extraction in log using RegEx? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/how-to-Configure-positional-timestamp-extraction-in-log-using/m-p/370146#M169842</link>
    <description>&lt;P&gt;hi All,&lt;/P&gt;

&lt;P&gt;Am trying to extract the time stamp inside event as index time. We have similar sourcetype of logs from 4 different indexes &lt;/P&gt;

&lt;P&gt;Apr 19 09:21:12 XYZADMXYZAB3P04 XYZADMXYZAB3P04 [customer] [426426|TaskExecutor-master-426426-ProcessTask [8797404726198]] [2018-04-19 09:21:11,929] [not present] [admin] [true]: Customer [&lt;A href="mailto:aubcdsatest@google.com"&gt;aubcdsatest@google.com&lt;/A&gt;] is created/updated&lt;BR /&gt;
Apr 25 15:00:44 XYZADMXYZAB3P04 XYZADMXYZAB3P04 [customer] [139468|TaskExecutor-master-139468-ProcessTask [8797864231862]] [2018-04-25 15:00:41,004] [not present] [admin] [true]: Customer [&lt;A href="mailto:m.abcsree40@gmail.com"&gt;m.abcsree40@gmail.com&lt;/A&gt;] is created/updated&lt;BR /&gt;
Apr  4 09:52:28 XYZECMXYZAB1P43 XYZECMXYZAB1P43 [customer] [103920|ajp-bio-8010-exec-158] [2018-04-04 09:52:21,843] [192.145.12.4] [&lt;A href="mailto:line.sssss@icloud.com"&gt;line.sssss@icloud.com&lt;/A&gt;] [true]: Customer [&lt;A href="mailto:lint.sre@icloud.com"&gt;lint.sre@icloud.com&lt;/A&gt;] is created/updated&lt;BR /&gt;
Apr  4 09:52:28 XYZECMXYZAB1P43 XYZECMXYZAB1P43 [authentication] [103920|ajp-bio-8010-exec-158] [2018-04-04 09:52:21,876] [192.145.12.4] [&lt;A href="mailto:abcd.sssss@icloud.com"&gt;abcd.sssss@icloud.com&lt;/A&gt;] [true]: user [&lt;A href="mailto:abcd.ssss@icloud.com"&gt;abcd.ssss@icloud.com&lt;/A&gt;] successfully authenticated&lt;BR /&gt;
Apr  9 12:41:52 XYZBUSXYZAB3P01 XYZBUSXYZAB3P01 [employee] [200061|hybrisHTTP8] [2018-04-09 12:41:48,609] [10.44.189.72] [anonymous] [true]: Employee [tester] is created/updated&lt;/P&gt;

&lt;P&gt;Apr 21 02:55:46 ABCPUBXYZAB56 ABCPUBXYZAB56 2018-04-21 02:55:39.800 INFO [com.xyxf.auth.core.XYLoginHookAuthenticationHandler] Activated XYZ authentication feedback handler wrap handler enabled is true&lt;BR /&gt;
Apr 12 08:23:06 ABCPUBXYZAB47 ABCPUBXYZAB47 2018-04-12 08:23:00.401 INFO [com.xyzf.auth.core.XYLoginHookAuthenticationHandler] 10.66.101.22 admin failed&lt;/P&gt;

&lt;P&gt;In the above logs how to extract the second timestamp as indextime. can someone help me with RegEx.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Sree&lt;/P&gt;</description>
    <pubDate>Sat, 28 Apr 2018 16:30:38 GMT</pubDate>
    <dc:creator>mallempatisreed</dc:creator>
    <dc:date>2018-04-28T16:30:38Z</dc:date>
    <item>
      <title>how to Configure positional timestamp extraction in log using RegEx?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-Configure-positional-timestamp-extraction-in-log-using/m-p/370146#M169842</link>
      <description>&lt;P&gt;hi All,&lt;/P&gt;

&lt;P&gt;Am trying to extract the time stamp inside event as index time. We have similar sourcetype of logs from 4 different indexes &lt;/P&gt;

&lt;P&gt;Apr 19 09:21:12 XYZADMXYZAB3P04 XYZADMXYZAB3P04 [customer] [426426|TaskExecutor-master-426426-ProcessTask [8797404726198]] [2018-04-19 09:21:11,929] [not present] [admin] [true]: Customer [&lt;A href="mailto:aubcdsatest@google.com"&gt;aubcdsatest@google.com&lt;/A&gt;] is created/updated&lt;BR /&gt;
Apr 25 15:00:44 XYZADMXYZAB3P04 XYZADMXYZAB3P04 [customer] [139468|TaskExecutor-master-139468-ProcessTask [8797864231862]] [2018-04-25 15:00:41,004] [not present] [admin] [true]: Customer [&lt;A href="mailto:m.abcsree40@gmail.com"&gt;m.abcsree40@gmail.com&lt;/A&gt;] is created/updated&lt;BR /&gt;
Apr  4 09:52:28 XYZECMXYZAB1P43 XYZECMXYZAB1P43 [customer] [103920|ajp-bio-8010-exec-158] [2018-04-04 09:52:21,843] [192.145.12.4] [&lt;A href="mailto:line.sssss@icloud.com"&gt;line.sssss@icloud.com&lt;/A&gt;] [true]: Customer [&lt;A href="mailto:lint.sre@icloud.com"&gt;lint.sre@icloud.com&lt;/A&gt;] is created/updated&lt;BR /&gt;
Apr  4 09:52:28 XYZECMXYZAB1P43 XYZECMXYZAB1P43 [authentication] [103920|ajp-bio-8010-exec-158] [2018-04-04 09:52:21,876] [192.145.12.4] [&lt;A href="mailto:abcd.sssss@icloud.com"&gt;abcd.sssss@icloud.com&lt;/A&gt;] [true]: user [&lt;A href="mailto:abcd.ssss@icloud.com"&gt;abcd.ssss@icloud.com&lt;/A&gt;] successfully authenticated&lt;BR /&gt;
Apr  9 12:41:52 XYZBUSXYZAB3P01 XYZBUSXYZAB3P01 [employee] [200061|hybrisHTTP8] [2018-04-09 12:41:48,609] [10.44.189.72] [anonymous] [true]: Employee [tester] is created/updated&lt;/P&gt;

&lt;P&gt;Apr 21 02:55:46 ABCPUBXYZAB56 ABCPUBXYZAB56 2018-04-21 02:55:39.800 INFO [com.xyxf.auth.core.XYLoginHookAuthenticationHandler] Activated XYZ authentication feedback handler wrap handler enabled is true&lt;BR /&gt;
Apr 12 08:23:06 ABCPUBXYZAB47 ABCPUBXYZAB47 2018-04-12 08:23:00.401 INFO [com.xyzf.auth.core.XYLoginHookAuthenticationHandler] 10.66.101.22 admin failed&lt;/P&gt;

&lt;P&gt;In the above logs how to extract the second timestamp as indextime. can someone help me with RegEx.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Sree&lt;/P&gt;</description>
      <pubDate>Sat, 28 Apr 2018 16:30:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-Configure-positional-timestamp-extraction-in-log-using/m-p/370146#M169842</guid>
      <dc:creator>mallempatisreed</dc:creator>
      <dc:date>2018-04-28T16:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: how to Configure positional timestamp extraction in log using RegEx?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-Configure-positional-timestamp-extraction-in-log-using/m-p/370147#M169843</link>
      <description>&lt;P&gt;Hi Mallempatisreeedhar, &lt;/P&gt;

&lt;P&gt;I wrote a regex that should help you extract the timestamps you want. &lt;/P&gt;

&lt;P&gt;Click here to see the regex. Also regex101 is a great site for developing those regexes.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://regex101.com/r/62Pfpn/1"&gt;https://regex101.com/r/62Pfpn/1&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you want a SPL example:&lt;BR /&gt;
&lt;CODE&gt;| rex field=_raw "\[?(?&amp;lt;time&amp;gt;20\d\d-\d\d-\d\d\s*\d\d:\d\d:\d\d(?:\,|\.)\d+)\[?"&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Apr 2018 20:27:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-Configure-positional-timestamp-extraction-in-log-using/m-p/370147#M169843</guid>
      <dc:creator>horsefez</dc:creator>
      <dc:date>2018-04-28T20:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: how to Configure positional timestamp extraction in log using RegEx?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-Configure-positional-timestamp-extraction-in-log-using/m-p/370148#M169844</link>
      <description>&lt;P&gt;@mallempatisreedhar , can you try this please:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rex "^.*(?=(\d{4}-\d+-\d+\s\d+:\d+:\d+[,.]\d+))(?&amp;lt;time&amp;gt;\d{4}-\d+-\d+\s\d+:\d+:\d+[,.]\d+)"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;if you want extract the time at parsing using sourcetype stanza props.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TIME_FORMAT=%Y-%m-%d %H:%M:%S
TIME_PREFIX=^.*(?=(\d{4}-\d+-\d+\s\d+:\d+:\d+[,.]\d+))
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 28 Apr 2018 20:49:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-Configure-positional-timestamp-extraction-in-log-using/m-p/370148#M169844</guid>
      <dc:creator>TISKAR</dc:creator>
      <dc:date>2018-04-28T20:49:15Z</dc:date>
    </item>
  </channel>
</rss>

