<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Timestamp Parsing in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Receiving-timestamp-parsing-error/m-p/593554#M206597</link>
    <description>&lt;P&gt;Thank you. These are the sample lines:&lt;/P&gt;&lt;P&gt;========&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Sat Mar 19 16:33:08 2022 -05:00&lt;/SPAN&gt;&lt;SPAN&gt; LENGTH : '228' ACTION :[7] 'CONNECT' DATABASE USER:[1] '/' PRIVILEGE :[6] 'SYSDBA' CLIENT USER:[6] 'oracle' CLIENT TERMINAL:[5] 'pts/1' STATUS:[1] '0' DBID:[0] '' SESSIONID:[0] '' USERHOST:[0] '' CLIENT ADDRESS:[0] '' ACTION NUMBER:[3] '100' Audit file /u01/app/oracle/product/19.3.0/dbhome_1/rdbms/audit/lllprd1_ora_44388_20220319163308485740872483.aud Oracle Database 19c Enterprise Edition Release 19.0.0.0.0 - Production Version 19.14.0.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Sat Mar 19 15:25:42 2022 -05:00&lt;/SPAN&gt; LENGTH : '228' ACTION :[7] 'CONNECT' DATABASE USER:[1] '/' PRIVILEGE :[6] 'SYSDBA' CLIENT USER:[6] 'oracle' CLIENT TERMINAL:[5] 'pts/1' STATUS:[1] '0' DBID:[0] '' SESSIONID:[0] '' USERHOST:[0] '' CLIENT ADDRESS:[0] '' ACTION NUMBER:[3] '100' Audit file /u01/app/oracle/product/19.3.0/dbhome_1/rdbms/audit/lllprd1_ora_4908_20220319152542116439456508.aud Oracle Database 19c Enterprise Edition Release 19.0.0.0.0 - Production&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;==============&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Apr 2022 06:11:24 GMT</pubDate>
    <dc:creator>vjsplunk</dc:creator>
    <dc:date>2022-04-13T06:11:24Z</dc:date>
    <item>
      <title>Receiving timestamp parsing error</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-timestamp-parsing-error/m-p/593534#M206586</link>
      <description>&lt;P&gt;I am trying to set timestamp for the event :&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;========&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Sat Mar 19 16:33:08 2022&lt;/SPAN&gt;&lt;SPAN&gt; -05:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;LENGTH : '228' &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ACTION :[7] 'CONNECT' &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;DATABASE USER:[1] '/'&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;=========&lt;/P&gt;
&lt;P&gt;The rules I used are:&lt;/P&gt;
&lt;P&gt;TIME_FORMAT =&amp;nbsp;%a %b %d %H:%M:%S %Y %:z&lt;/P&gt;
&lt;P&gt;TIME_PREFIX = ^&lt;/P&gt;
&lt;P&gt;MAX_TIMESTAMP_LOOKAHEAD = 32&lt;/P&gt;
&lt;P&gt;It is catching the timestamp correctly. However showing the error "could not use strptime to parse timestamp from&amp;nbsp;&lt;SPAN&gt;LENGTH : '228' "&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am not sure how to resolve the error.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 15:09:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-timestamp-parsing-error/m-p/593534#M206586</guid>
      <dc:creator>vjsplunk</dc:creator>
      <dc:date>2022-04-13T15:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp Parsing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-timestamp-parsing-error/m-p/593548#M206593</link>
      <description>&lt;P&gt;Have you set the following attributes properly? It seems an issue with the line-breaking or line-merging because Splunk is also trying to parse the timestamp on the second line as well.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;SHOULD_LINEMERGE&lt;/LI&gt;&lt;LI&gt;LINE_BREAKER&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 13 Apr 2022 05:49:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-timestamp-parsing-error/m-p/593548#M206593</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-04-13T05:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp Parsing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-timestamp-parsing-error/m-p/593550#M206594</link>
      <description>&lt;P&gt;Yes. I have applied the below 2 rules:&lt;/P&gt;&lt;P&gt;LINE_BREAKER =&amp;nbsp;([\r\n]+)&lt;/P&gt;&lt;P&gt;SHOULD_LINEMERGE = true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Line breaking is proper. Not sure it is showing the error&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 06:01:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-timestamp-parsing-error/m-p/593550#M206594</guid>
      <dc:creator>vjsplunk</dc:creator>
      <dc:date>2022-04-13T06:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp Parsing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-timestamp-parsing-error/m-p/593553#M206596</link>
      <description>&lt;P&gt;If SHOULD_LINEMERGE=true then you have specified when to break the event.&lt;/P&gt;&lt;P&gt;I would suggest using SHOULD_LINEMERGE=false and updating the LINE_BREAKER accordingly. (Gives better performance and hopefully resolves your error too.)&lt;/P&gt;&lt;P&gt;Please provide two-three sample events as they are in the file and I can help you write the LINE_BREAKER.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 06:06:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-timestamp-parsing-error/m-p/593553#M206596</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-04-13T06:06:22Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp Parsing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-timestamp-parsing-error/m-p/593554#M206597</link>
      <description>&lt;P&gt;Thank you. These are the sample lines:&lt;/P&gt;&lt;P&gt;========&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Sat Mar 19 16:33:08 2022 -05:00&lt;/SPAN&gt;&lt;SPAN&gt; LENGTH : '228' ACTION :[7] 'CONNECT' DATABASE USER:[1] '/' PRIVILEGE :[6] 'SYSDBA' CLIENT USER:[6] 'oracle' CLIENT TERMINAL:[5] 'pts/1' STATUS:[1] '0' DBID:[0] '' SESSIONID:[0] '' USERHOST:[0] '' CLIENT ADDRESS:[0] '' ACTION NUMBER:[3] '100' Audit file /u01/app/oracle/product/19.3.0/dbhome_1/rdbms/audit/lllprd1_ora_44388_20220319163308485740872483.aud Oracle Database 19c Enterprise Edition Release 19.0.0.0.0 - Production Version 19.14.0.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Sat Mar 19 15:25:42 2022 -05:00&lt;/SPAN&gt; LENGTH : '228' ACTION :[7] 'CONNECT' DATABASE USER:[1] '/' PRIVILEGE :[6] 'SYSDBA' CLIENT USER:[6] 'oracle' CLIENT TERMINAL:[5] 'pts/1' STATUS:[1] '0' DBID:[0] '' SESSIONID:[0] '' USERHOST:[0] '' CLIENT ADDRESS:[0] '' ACTION NUMBER:[3] '100' Audit file /u01/app/oracle/product/19.3.0/dbhome_1/rdbms/audit/lllprd1_ora_4908_20220319152542116439456508.aud Oracle Database 19c Enterprise Edition Release 19.0.0.0.0 - Production&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;==============&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 06:11:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-timestamp-parsing-error/m-p/593554#M206597</guid>
      <dc:creator>vjsplunk</dc:creator>
      <dc:date>2022-04-13T06:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp Parsing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-timestamp-parsing-error/m-p/593555#M206598</link>
      <description>&lt;P&gt;It seems you have a single line event, use &lt;STRONG&gt;SHOULD_LINEMERGE=false&lt;/STRONG&gt; then along with your current configuration.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 06:19:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-timestamp-parsing-error/m-p/593555#M206598</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-04-13T06:19:42Z</dc:date>
    </item>
  </channel>
</rss>

