<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: To display actual logs time by using Timechart command in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312524#M93557</link>
    <description>&lt;P&gt;Hi @Sagar0511,&lt;BR /&gt;
Can you please provide more details?&lt;/P&gt;</description>
    <pubDate>Mon, 27 Nov 2017 12:41:38 GMT</pubDate>
    <dc:creator>kamlesh_vaghela</dc:creator>
    <dc:date>2017-11-27T12:41:38Z</dc:date>
    <item>
      <title>To display actual logs time by using Timechart command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312523#M93556</link>
      <description>&lt;P&gt;Hi Everyone&lt;/P&gt;

&lt;P&gt;I am trying to create a timechart report and I want to display the Output of the Log event time field instead of &lt;STRONG&gt;_time&lt;/STRONG&gt; which is uploaded event time. I tried with the timechart command but it couldn't work. I think by default it takes the field "_time". I have tried rename the logs Time(extarcetd from the Logs) to Time(Actual time of Logs) by the command "&lt;STRONG&gt;eval _time=Time&lt;/STRONG&gt;".&lt;/P&gt;

&lt;P&gt;Find the snapshot for the sample Log file data&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="img"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3937i721772161B15801E/image-size/large?v=v2&amp;amp;px=999" role="button" title="img" alt="img" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 12:31:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312523#M93556</guid>
      <dc:creator>Sagar0511</dc:creator>
      <dc:date>2017-11-27T12:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: To display actual logs time by using Timechart command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312524#M93557</link>
      <description>&lt;P&gt;Hi @Sagar0511,&lt;BR /&gt;
Can you please provide more details?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 12:41:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312524#M93557</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2017-11-27T12:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: To display actual logs time by using Timechart command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312525#M93558</link>
      <description>&lt;P&gt;What, specifically, do you want to display, and why do you want to use &lt;CODE&gt;timechart&lt;/CODE&gt;?&lt;/P&gt;

&lt;P&gt;Timechart is really great for summarizing the flow of events, but it's just not usable for exact time data. &lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 17:31:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312525#M93558</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-11-27T17:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: To display actual logs time by using Timechart command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312526#M93559</link>
      <description>&lt;P&gt;apologies... edited my original post now to show more details (formerly hidden in image tag)&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 05:44:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312526#M93559</guid>
      <dc:creator>Sagar0511</dc:creator>
      <dc:date>2017-11-28T05:44:23Z</dc:date>
    </item>
    <item>
      <title>Re: To display actual logs time by using Timechart command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312527#M93560</link>
      <description>&lt;P&gt;@Sagar0511, can you add raw sample event data (mock/anonymize any sensitive information). Also tell us in the raw event as to what is the log time. Seems like your logs may have two time stamps and your &lt;CODE&gt;props.conf&lt;/CODE&gt; setting is using the incorrect field as event timestamp or &lt;CODE&gt;_time&lt;/CODE&gt;, which you would need to rectify. Share your props.conf will also be helpful.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 05:51:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312527#M93560</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-11-28T05:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: To display actual logs time by using Timechart command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312528#M93561</link>
      <description>&lt;P&gt;The device is not sending the logs directly to splunk server. Instead i have a csv log file which i let rsyslog (on another ubuntu system) send to the splunk server. Hence the &lt;STRONG&gt;_time&lt;/STRONG&gt; value is the rsyslog transmit time, whereas the &lt;STRONG&gt;Time&lt;/STRONG&gt; is the actual log timestamp.&lt;/P&gt;

&lt;P&gt;Sample log (1 event) below:&lt;BR /&gt;
&amp;lt;133&amp;gt;Oct 23 07:25:25 ubuntu CPFW, 217,26Oct2017,23:59:00,eth1-02,10.2.2.189,Log,Accept,53,54080,10.28.0.16,165.21.100.88,udp,203,,203-CBIG-SIN-Consolidation,,service_id: domain-udp,Security Gateway/Management,,&lt;/P&gt;

&lt;P&gt;rsyslog time is Oct 23 07:25:25 = _time&lt;/P&gt;

&lt;P&gt;actual log time is 23:59:00 = Time&lt;/P&gt;

&lt;P&gt;I have used field extraction feature of splunk to specify the comma delimited nature of the log. The result of the field extraction is shown in my original post.&lt;/P&gt;

&lt;P&gt;Below props.conf file from Splunk/etc/system/local&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[Hostnames]
DATETIME_CONFIG = 
INDEXED_EXTRACTIONS = csv
KV_MODE = none
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = false
category = Structured
description = Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled = false
pulldown_type = true

[CBIG-SIN_Log1 Updated]
DATETIME_CONFIG = 
INDEXED_EXTRACTIONS = csv
KV_MODE = none
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = false
category = Structured
description = Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled = false
pulldown_type = true

[csv]
DATETIME_CONFIG = 
FIELD_DELIMITER = space
FIELD_QUOTE = "
NO_BINARY_CHECK = true
disabled = false

[CBIG_SING_Log1]
DATETIME_CONFIG = 
FIELD_DELIMITER = space
FIELD_QUOTE = "
INDEXED_EXTRACTIONS = csv
KV_MODE = none
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = false
category = Structured
description = Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled = false
pulldown_type = true

[test1]
DATETIME_CONFIG = 
FIELD_DELIMITER = ,
FIELD_QUOTE = "
INDEXED_EXTRACTIONS = csv
KV_MODE = none
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = false
category = Structured
description = Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled = false
pulldown_type = true

[test]
DATETIME_CONFIG = 
FIELD_DELIMITER = ,
FIELD_QUOTE = "
INDEXED_EXTRACTIONS = csv
KV_MODE = none
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = false
category = Structured
description = Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled = false
pulldown_type = true

[CBIG_SIN]
DATETIME_CONFIG = 
FIELD_DELIMITER = space
FIELD_QUOTE = "
INDEXED_EXTRACTIONS = csv
KV_MODE = none
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = false
category = Structured
description = Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled = false
pulldown_type = true

[cbig_sin]
DATETIME_CONFIG = 
FIELD_DELIMITER = space
FIELD_QUOTE = "
INDEXED_EXTRACTIONS = csv
KV_MODE = none
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = false
category = Structured
description = Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled = false
pulldown_type = true

[access_combined1]
DATETIME_CONFIG = 
FIELD_DELIMITER = ,
FIELD_QUOTE = "
INDEXED_EXTRACTIONS = csv
KV_MODE = none
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = false
category = Structured
description = Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled = false
pulldown_type = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;edit: sourcetype for the events we are referring in this question is 'cplogs'.. which can't be seen in props.conf&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 06:26:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312528#M93561</guid>
      <dc:creator>Sagar0511</dc:creator>
      <dc:date>2017-11-28T06:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: To display actual logs time by using Timechart command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312529#M93562</link>
      <description>&lt;P&gt;@Sagar0511, is your event timestamp supposed to be &lt;CODE&gt;26Oct2017,23:59:00&lt;/CODE&gt;. Does your CSV file have a header? If so, what are these field names called? Which stanza in the props.conf applies to the above event? It should be the same as the &lt;CODE&gt;sourcetype&lt;/CODE&gt;, that Splunk Search displays when you search raw data.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 06:44:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312529#M93562</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-11-28T06:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: To display actual logs time by using Timechart command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312530#M93563</link>
      <description>&lt;P&gt;Yes, the event timestamp is 26Oct2017,23:59:00. The header is present in the csv log file but I have extracted the field names by doing field extraction; so in that there is no need of headers. There is no cplogs(Sourcetype) mentioned in the props.conf which has been uploaded in the previous post.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 13:24:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312530#M93563</guid>
      <dc:creator>Sagar0511</dc:creator>
      <dc:date>2017-11-28T13:24:16Z</dc:date>
    </item>
    <item>
      <title>Re: To display actual logs time by using Timechart command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312531#M93564</link>
      <description>&lt;P&gt;Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | eval DateTime = Date . " " . Time
| eval _time = strptime(DateTime, "%d%b%Y %H:%M:%S")
| timechart foo bar blah
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 02 Dec 2017 03:45:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312531#M93564</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-12-02T03:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: To display actual logs time by using Timechart command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312532#M93565</link>
      <description>&lt;P&gt;@Sagar0511, I was trying to see a feasibility of getting Date and Time fields from CSV clubbed as _time (event time) at the time of indexing itself using props.conf. So that you dont have to put additional load for the same at Search Time. However, if you are performing a Field Extraction during Search Time, then you can try @woodcock 's answer.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Dec 2017 17:00:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312532#M93565</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-12-02T17:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: To display actual logs time by using Timechart command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312533#M93566</link>
      <description>&lt;P&gt;The Query had successfully executed and desired result has been achieved. Thank you very much.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 05:42:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/To-display-actual-logs-time-by-using-Timechart-command/m-p/312533#M93566</guid>
      <dc:creator>Sagar0511</dc:creator>
      <dc:date>2017-12-06T05:42:30Z</dc:date>
    </item>
  </channel>
</rss>

