<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Date Format and Time Format in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Date-Format-and-Time-Format/m-p/563097#M196186</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;just a little update:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME_PREFIX=^
TIME_FORMAT=%Y-%m-%dT%H:%M:%S.%6N%:z&lt;/LI-CODE&gt;&lt;P&gt;because you have 6 milliseconds digits and in your timezone you have the format -5:00&lt;/P&gt;&lt;P&gt;For more infos see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.1/SearchReference/Commontimeformatvariables" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.1/SearchReference/Commontimeformatvariables&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 12 Aug 2021 16:09:40 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-08-12T16:09:40Z</dc:date>
    <item>
      <title>Date Format and Time Format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Date-Format-and-Time-Format/m-p/563094#M196185</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;What would be my TIME_FORMAT for prop configuration file for this events&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2021-06-08T13:26:53.665000-04:00|PGM|mtb1120ppcdwap6|vggtb|26462|&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2021-06-08T13:26:54.478000-04:00|PGM|mtb1120ppcdwap6|vggtb|26462|&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;STRONG&gt;I wrote this not covering entire range&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;TIME_PREFIX=^&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;TIME_FORMAT=%Y-%m-%dT%H:%M:%S.%f%z&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;Any help will be highly appreciated. Thank you so much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 15:54:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Date-Format-and-Time-Format/m-p/563094#M196185</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-12T15:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: Date Format and Time Format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Date-Format-and-Time-Format/m-p/563097#M196186</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;just a little update:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME_PREFIX=^
TIME_FORMAT=%Y-%m-%dT%H:%M:%S.%6N%:z&lt;/LI-CODE&gt;&lt;P&gt;because you have 6 milliseconds digits and in your timezone you have the format -5:00&lt;/P&gt;&lt;P&gt;For more infos see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.1/SearchReference/Commontimeformatvariables" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.1/SearchReference/Commontimeformatvariables&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 16:09:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Date-Format-and-Time-Format/m-p/563097#M196186</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-08-12T16:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: Date Format and Time Format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Date-Format-and-Time-Format/m-p/563098#M196187</link>
      <description>&lt;P&gt;Perfect ...working as expected, thank you so much ...appreciated.....just one more issue... my source is text file....how would I make my PROPS Conf file not to read first line ....as first line is not an event..&lt;/P&gt;&lt;P&gt;ost: 'XXXpcdwa', OS: 'LIN X64', Release: '35.0.0-X1127.19.1.ex7.x86_128',&amp;nbsp; Version: '&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2021-06-08T13:26:53.665000-04:00|PGM|mtb1120ppcdwap6|vggtb|26462|&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2021-06-08T13:26:54.478000-04:00|PGM|mtb1120ppcdwap6|vggtb|26462|&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 16:26:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Date-Format-and-Time-Format/m-p/563098#M196187</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-12T16:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: Date Format and Time Format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Date-Format-and-Time-Format/m-p/563099#M196188</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, please accept my answer for the other people of Community.&lt;/P&gt;&lt;P&gt;About log filtering, if you can find a regex (e.g. in your case "^ost:"), you can filter your data flow excluding events that match the regex, following the configuration at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Forwarding/Routeandfilterdatad#Discard_specific_events_and_keep_the_rest" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Forwarding/Routeandfilterdatad#Discard_specific_events_and_keep_the_rest&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In your case:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;props.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[your_sourcetype]
TRANSFORMS-null= setnull&lt;/LI-CODE&gt;&lt;P&gt;transforms.conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[setnull]
REGEX = ^ost:
DEST_KEY = queue
FORMAT = nullQueue&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 16:33:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Date-Format-and-Time-Format/m-p/563099#M196188</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-08-12T16:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Date Format and Time Format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Date-Format-and-Time-Format/m-p/563104#M196192</link>
      <description>&lt;P&gt;Hello, since event has the pipe "|" ...I wanted to use following props conf ...but not working.., any help will be highly appreciated!&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;SHOULD_LINEMERGE = false&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;LINE_BREAKER = ([\r\n]+)&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;INDEXED_EXTRACTIONS = psv&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;TIME_FORMAT = %Y%m%d %H:%M:%S:%Q&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;TIMESTAMP_FIELDS = TIMESTAMP&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 17:08:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Date-Format-and-Time-Format/m-p/563104#M196192</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-12T17:08:38Z</dc:date>
    </item>
    <item>
      <title>Re: Date Format and Time Format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Date-Format-and-Time-Format/m-p/563149#M196213</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;to use indexed extractions, you have to define:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the kind of indexed extraction, in your case psv,&lt;/LI&gt;&lt;LI&gt;the separator, in your case pipe "|",&lt;/LI&gt;&lt;LI&gt;the field list.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;About timestamp, if it's raining the above extraction, I'd use it&lt;/P&gt;&lt;P&gt;Anyway, please try something like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;SHOULD_LINEMERGE = false
LINE_BREAKER = ([\r\n]+)
INDEXED_EXTRACTIONS = psv
TIME_PREFIX=^
TIME_FORMAT=%Y-%m-%dT%H:%M:%S.%6N%:z
TIMESTAMP_FIELDS = TIMESTAMP
PREAMBLE_REGEX = ^ost:
FIELD_DELIMITER = |
FIELD_NAMES = TimeStamp, field2, field3, field4, field5&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 07:03:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Date-Format-and-Time-Format/m-p/563149#M196213</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-08-13T07:03:05Z</dc:date>
    </item>
  </channel>
</rss>

