<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Time format for &amp;quot;raw&amp;quot; messages in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/619839#M215425</link>
    <description>&lt;P&gt;"&lt;SPAN&gt;Please use a code block using the &amp;lt;/&amp;gt; format option."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Where is there a manual on how to properly highlight code with tags?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Nov 2022 10:31:36 GMT</pubDate>
    <dc:creator>metylkinandrey</dc:creator>
    <dc:date>2022-11-07T10:31:36Z</dc:date>
    <item>
      <title>What is the correct time format for "raw" messages?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/619808#M215406</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Good afternoon!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I'm noticing that my time format in the messages I send to /services/collector/raw isn't being parsed, or even vice versa, this field isn't displayed in splunk.&lt;BR /&gt;My field is: "eventTime": "2022-10-13T18:08:30",&lt;BR /&gt;Please tell me the correct format.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 15:44:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/619808#M215406</guid>
      <dc:creator>metylkinandrey</dc:creator>
      <dc:date>2022-11-08T15:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: Time format for "raw" messages</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/619815#M215411</link>
      <description>&lt;LI-CODE lang="markup"&gt;%Y-%m-%dT%T&lt;/LI-CODE&gt;&lt;P&gt;Time format variables are described&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Commontimeformatvariables" target="_self"&gt;here&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 08:24:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/619815#M215411</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-11-07T08:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Time format for "raw" messages</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/619828#M215417</link>
      <description>&lt;P&gt;Yes, I understand how to process it, but what if the field is not displayed at all?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 10:04:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/619828#M215417</guid>
      <dc:creator>metylkinandrey</dc:creator>
      <dc:date>2022-11-07T10:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: Time format for "raw" messages</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/619829#M215418</link>
      <description>&lt;P&gt;I am not sure I understand - are you saying the field does not appear in your events?&lt;/P&gt;&lt;P&gt;Please can you share some anonymised _raw events, some where it is working and some where it is not?&lt;/P&gt;&lt;P&gt;Please use a code block using the &amp;lt;/&amp;gt; format option.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 10:08:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/619829#M215418</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-11-07T10:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: Time format for "raw" messages</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/619832#M215420</link>
      <description>&lt;P&gt;Yes, you got it right.&lt;BR /&gt;I send a message like this:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;'{&lt;BR /&gt;"messageId": "ED280816-E404-444A-A2D9-FFD2D171F323",&lt;BR /&gt;"messageType": "RABIS-HeartBeat",&lt;BR /&gt;"eventTime": "2022-10-13T18:08:00",&lt;BR /&gt;}'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But I only see the first two fields. I indicated in the screenshot.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 10:30:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/619832#M215420</guid>
      <dc:creator>metylkinandrey</dc:creator>
      <dc:date>2022-11-07T10:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: Time format for "raw" messages</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/619839#M215425</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;Please use a code block using the &amp;lt;/&amp;gt; format option."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Where is there a manual on how to properly highlight code with tags?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 10:31:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/619839#M215425</guid>
      <dc:creator>metylkinandrey</dc:creator>
      <dc:date>2022-11-07T10:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: Time format for "raw" messages</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/619845#M215429</link>
      <description>&lt;P&gt;How are you extracting the fields?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 10:51:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/619845#M215429</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-11-07T10:51:26Z</dc:date>
    </item>
    <item>
      <title>Re: Time format for "raw" messages</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/619863#M215440</link>
      <description>&lt;P&gt;In this case, no way, since this field is not there anyway.&lt;BR /&gt;As an alternative for the remaining two fields, I use this query:&lt;/P&gt;&lt;P&gt;index="external_system" messageType="RABIS-HeartBeat"&lt;BR /&gt;| eval timeValue='eventTime'&lt;BR /&gt;| eval time=strptime(timeValue,"%Y-%m-%dT%H:%M:%S.")&lt;BR /&gt;| sort -eventTime&lt;BR /&gt;| eval timeValue='eventTime'&lt;BR /&gt;| eval time=strptime(timeValue,"%Y-%m-%dT%H:%M:%S.")&lt;BR /&gt;| sort -eventTime&lt;BR /&gt;| streamstats values(time) current=f window=1 as STERAM_RESULT global=false by messageType&lt;BR /&gt;| eval diff=STERAM_RESULT-time&lt;BR /&gt;| stats list(eventTime) as EventTime list(messageType) as MessageType list(messageId) as MessageId by messageType&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 11:39:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/619863#M215440</guid>
      <dc:creator>metylkinandrey</dc:creator>
      <dc:date>2022-11-07T11:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: Time format for "raw" messages</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/620086#M215539</link>
      <description>&lt;P&gt;esterday I tested a lot and realized that this message format works every other time:&lt;/P&gt;&lt;P&gt;curl --location --request POST '&lt;A href="http://10.10.10.10:8088/services/collector/raw" target="_blank" rel="nofollow noopener noreferrer"&gt;http://10.10.10.10:8088/services/collector/raw&lt;/A&gt;' --header 'Authorization: Splunk a2-a2-a2' --header 'Content-Type: text/plain' --data-raw '{&lt;BR /&gt;"messageId": "ED280816-E404-444A-A2D9-FFD2D171F111",&lt;BR /&gt;"messageType": "RABIS-HeartBeat",&lt;BR /&gt;"eventTime": "1985-04-12T23:21:15"&lt;BR /&gt;}'&lt;/P&gt;&lt;P&gt;I just saw that the correct messages have 23 spaces, the problematic ones have 22. Not the point, I just copy the correct messages - for the test, we can assume that I figured it out.&lt;/P&gt;&lt;P&gt;The problem remains with messages where the field is: "eventTime": "1985-04-12T23:21:15" in the middle. I have no guarantee that it will be different in production.&lt;BR /&gt;Here is an example:&lt;BR /&gt;curl --location --request POST '&lt;A href="http://10.10.10.10:8088/services/collector/raw" target="_blank" rel="nofollow noopener noreferrer"&gt;http://10.10.10.10:8088/services/collector/raw&lt;/A&gt;' --header 'Authorization: Splunk a24-a24-a24-a24' --header 'Content-Type: text/plain' --data-raw '{&lt;BR /&gt;"messageId": "ED280816-E404-444A-A2D9-FFD2D171F136",&lt;BR /&gt;"eventTime": "2022-11-07T17:06:15",&lt;BR /&gt;"messageType": "RABIS-HeartBeat"&lt;BR /&gt;}'&lt;/P&gt;&lt;P&gt;In this case, I can't find messages at all in the splank index. Although I can see that it was sent successfully in the bash console.&lt;BR /&gt;Splank doesn't like our format(( This is how he likes it: 2022-11-0717:06:15&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 11:19:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-the-correct-time-format-for-quot-raw-quot-messages/m-p/620086#M215539</guid>
      <dc:creator>metylkinandrey</dc:creator>
      <dc:date>2022-11-08T11:19:45Z</dc:date>
    </item>
  </channel>
</rss>

