Getting Data In

Any idea on where I am going wrong with bash_history timestamping?

daniel333
Builder

All,

I am extracting bash_history, the event looks like this.

#1510170881
grep -r something *

But ends up with this timestamp
5/23/18 12:05:39.000 PM

I believe it should be
5/23/18 22:08:30.000 PM

My props.conf looks like this -

[bash_history]
 BREAK_ONLY_BEFORE = #(?=\d+)
 MAX_TIMESTAMP_LOOKAHEAD = 11
 SHOULD_LINEMERGE = true
 TIME_FORMAT = %s
 TIME_PREFIX = #
 TRANSFORMS-bashhistory = route_to_indexers

Any ideas where I might be going wrong with this?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Is the bash_history file in a different time zone from your Splunk account setting?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...