<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Format a log message with a timestamp in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Format-a-log-message-with-a-timestamp/m-p/100831#M26032</link>
    <description>&lt;P&gt;Why sometimes the value of the timestamp is none when i add events to the splunk server?&lt;BR /&gt;
"In most cases, Splunk will do the right thing with timestamps, but there are situations where you might need to configure timestamp handling." Is that the reason why?&lt;/P&gt;</description>
    <pubDate>Mon, 26 Mar 2012 06:41:15 GMT</pubDate>
    <dc:creator>misteryuku</dc:creator>
    <dc:date>2012-03-26T06:41:15Z</dc:date>
    <item>
      <title>Format a log message with a timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Format-a-log-message-with-a-timestamp/m-p/100829#M26030</link>
      <description>&lt;P&gt;How do i format a log message with a timestamp so that when i send the log message to the splunk server i am able to see the timestamp when i open up the search app.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2012 04:19:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Format-a-log-message-with-a-timestamp/m-p/100829#M26030</guid>
      <dc:creator>misteryuku</dc:creator>
      <dc:date>2012-03-26T04:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: Format a log message with a timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Format-a-log-message-with-a-timestamp/m-p/100830#M26031</link>
      <description>&lt;P&gt;Most events don't require any special timestamp handling. Splunk automatically recognizes and extracts their timestamps...&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.1/Data/Configuretimestamprecognition"&gt;Configure timestamp recognition&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2012 06:09:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Format-a-log-message-with-a-timestamp/m-p/100830#M26031</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-03-26T06:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: Format a log message with a timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Format-a-log-message-with-a-timestamp/m-p/100831#M26032</link>
      <description>&lt;P&gt;Why sometimes the value of the timestamp is none when i add events to the splunk server?&lt;BR /&gt;
"In most cases, Splunk will do the right thing with timestamps, but there are situations where you might need to configure timestamp handling." Is that the reason why?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2012 06:41:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Format-a-log-message-with-a-timestamp/m-p/100831#M26032</guid>
      <dc:creator>misteryuku</dc:creator>
      <dc:date>2012-03-26T06:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Format a log message with a timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Format-a-log-message-with-a-timestamp/m-p/100832#M26033</link>
      <description>&lt;P&gt;The timestamp created is at the left hand side of the event row. is that it?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2012 06:46:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Format-a-log-message-with-a-timestamp/m-p/100832#M26033</guid>
      <dc:creator>misteryuku</dc:creator>
      <dc:date>2012-03-26T06:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Format a log message with a timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Format-a-log-message-with-a-timestamp/m-p/100833#M26034</link>
      <description>&lt;P&gt;yes that's the timestamp splunk assigned to the event.&lt;BR /&gt;
some rare occasions you need to point to splunk where is the timestamp and what format,you do that as per the link i put in my answer.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2012 12:02:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Format-a-log-message-with-a-timestamp/m-p/100833#M26034</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-04-05T12:02:39Z</dc:date>
    </item>
  </channel>
</rss>

