<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: can i configure milliseconds in splunk for the incomin events ?? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/can-i-configure-milliseconds-in-splunk-for-the-incomin-events/m-p/31641#M178117</link>
    <description>&lt;P&gt;Aah, sorry about that - wasn't aware of those limitations at the time of writing. I don't know if Splunk can be configured to store the _indextime with sub-seconds, but I doubt it.&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
    <pubDate>Mon, 03 Sep 2012 07:06:11 GMT</pubDate>
    <dc:creator>kristian_kolb</dc:creator>
    <dc:date>2012-09-03T07:06:11Z</dc:date>
    <item>
      <title>can i configure milliseconds in splunk for the incomin events ??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/can-i-configure-milliseconds-in-splunk-for-the-incomin-events/m-p/31637#M178113</link>
      <description>&lt;P&gt;HI.&lt;/P&gt;

&lt;P&gt;In my events i have the timestamp like HH:MM:SS seconds..So splunk is defaultly taking this timestamp.but i need to have the milliseconds also to do some stats. How can configure setttings in splunk in such a way that when ever each event comes to splunk...i need to show the time in current system time i.e time at which event came to splunk including the milliseconds in the time...&lt;/P&gt;

&lt;P&gt;My Sample Logg event is as follows ..&lt;/P&gt;

&lt;P&gt;**&lt;/P&gt;

&lt;P&gt;Jul 25 11:52:03 10.230.189.141 Jul 25 11:52:04 System: 0199B1  X0000000  0C00D  D  Configuration export a succeeded&lt;/P&gt;

&lt;P&gt;**&lt;/P&gt;

&lt;P&gt;Please help asap.&lt;/P&gt;

&lt;P&gt;Thanx&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2012 10:31:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/can-i-configure-milliseconds-in-splunk-for-the-incomin-events/m-p/31637#M178113</guid>
      <dc:creator>rakesh_498115</dc:creator>
      <dc:date>2012-08-10T10:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: can i configure milliseconds in splunk for the incomin events ??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/can-i-configure-milliseconds-in-splunk-for-the-incomin-events/m-p/31638#M178114</link>
      <description>&lt;P&gt;Maybe this can help you along,&lt;/P&gt;

&lt;P&gt;Each event has a hidden field called &lt;CODE&gt;_indextime&lt;/CODE&gt;, which is the local time of the indexer at the time the event was indexed. I believe(?) that unfortunately it cannot be accessed directly, say like in a &lt;CODE&gt;table&lt;/CODE&gt; or &lt;CODE&gt;chart&lt;/CODE&gt;, but you can &lt;CODE&gt;eval xxx=_indextime&lt;/CODE&gt; and use xxx for presentation purposes.&lt;/P&gt;

&lt;P&gt;For a little more info, see:&lt;BR /&gt;
[&lt;A href="http://splunk-base.splunk.com/answers/171/using-_indextime-to-specify-time-range%5D%5B1"&gt;http://splunk-base.splunk.com/answers/171/using-_indextime-to-specify-time-range][1&lt;/A&gt;]&lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;/P&gt;

&lt;P&gt;Kristian&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2012 11:45:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/can-i-configure-milliseconds-in-splunk-for-the-incomin-events/m-p/31638#M178114</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-08-10T11:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: can i configure milliseconds in splunk for the incomin events ??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/can-i-configure-milliseconds-in-splunk-for-the-incomin-events/m-p/31639#M178115</link>
      <description>&lt;P&gt;even i use the _indextime..i am gettin the milliseconds as 0 . i have used like this  eval Time=strftime(_indextime,"%H:%M:%S:%6N")  . but this not workin ?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:14:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/can-i-configure-milliseconds-in-splunk-for-the-incomin-events/m-p/31639#M178115</guid>
      <dc:creator>rakesh_498115</dc:creator>
      <dc:date>2020-09-28T12:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: can i configure milliseconds in splunk for the incomin events ??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/can-i-configure-milliseconds-in-splunk-for-the-incomin-events/m-p/31640#M178116</link>
      <description>&lt;P&gt;splunk is not taking the time format in milliseconds...ie i am unable to get the milliseconds value for my time .when i  use the _indextime... &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2012 15:27:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/can-i-configure-milliseconds-in-splunk-for-the-incomin-events/m-p/31640#M178116</guid>
      <dc:creator>rakesh_498115</dc:creator>
      <dc:date>2012-08-31T15:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: can i configure milliseconds in splunk for the incomin events ??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/can-i-configure-milliseconds-in-splunk-for-the-incomin-events/m-p/31641#M178117</link>
      <description>&lt;P&gt;Aah, sorry about that - wasn't aware of those limitations at the time of writing. I don't know if Splunk can be configured to store the _indextime with sub-seconds, but I doubt it.&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Mon, 03 Sep 2012 07:06:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/can-i-configure-milliseconds-in-splunk-for-the-incomin-events/m-p/31641#M178117</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-09-03T07:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: can i configure milliseconds in splunk for the incomin events ??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/can-i-configure-milliseconds-in-splunk-for-the-incomin-events/m-p/31642#M178118</link>
      <description>&lt;P&gt;We are looking for an answer to this too at my client this week. Basically, how to give an enterprise application more precision.&lt;/P&gt;

&lt;P&gt;The best option is to have the app itself write in millisecond precision. This eliminates all differences due to network lag, indexing lag (Splunk has buffers, so events may not be indexed instantly) etc.&lt;/P&gt;

&lt;P&gt;(&lt;I&gt;ANY other type of sub-second statistics, by definition, are not going to be fully accurate!&lt;/I&gt; ...due to the amount of time the event takes to get out of the application, across the network, and in to the Splunk server. So you should question whether or not it is even worth giving this type of stat out to your user, because their expectation could be set on something inherently inaccurate.)&lt;/P&gt;

&lt;P&gt;Since this does not seem to be an option until a further release of the application in question, we are going to try to eliminate as many Splunk variables as possible by using a syslog server (syslog-ng) to accept the syslog traffic and write a millisecond timestamp as to when it was received.&lt;/P&gt;

&lt;P&gt;It seems syslog-ng's "frac_digits" option can be used, either in a global options{} statement, or per "destination" - such as the file Splunk will monitor.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2012 12:43:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/can-i-configure-milliseconds-in-splunk-for-the-incomin-events/m-p/31642#M178118</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2012-09-25T12:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: can i configure milliseconds in splunk for the incomin events ??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/can-i-configure-milliseconds-in-splunk-for-the-incomin-events/m-p/31643#M178119</link>
      <description>&lt;P&gt;Thanx jason..It Worked &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Sep 2012 07:54:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/can-i-configure-milliseconds-in-splunk-for-the-incomin-events/m-p/31643#M178119</guid>
      <dc:creator>rakesh_498115</dc:creator>
      <dc:date>2012-09-29T07:54:47Z</dc:date>
    </item>
  </channel>
</rss>

