Getting Data In

Can't extract simple YYYYMMDD data to be event date...

philip_wong
Communicator

I have PSV files in such format. Date is in 2nd column.
Haven't spent much time to try different setting, but Splunk still took file modified time as event time stamp. I'm stilling asking myself what's wrong with "TIME_FORMAT= %Y%m%d"??

Anyone can help to see what's wrong of my props.conf?

foo|20131201|bar|...

[unixops:sitelog]
SHOULD_LINEMERGE = false
TIME_FORMAT= %Y%m%d
LEARN_MODEL = false
INDEXED_EXTRACTIONS = PSV
FIELD_NAMES = host,date,log,message_type,region,city,campus,building,status,personality

Tags (2)
1 Solution

philip_wong
Communicator

It works now. A silly mistake...

I didn't pay attention TIME_PREFIX is regex based.
So the answer is

TIME_PREFIX = \|

Thanks helping me!

View solution in original post

philip_wong
Communicator

It works now. A silly mistake...

I didn't pay attention TIME_PREFIX is regex based.
So the answer is

TIME_PREFIX = \|

Thanks helping me!

strive
Influencer

Good to know that it worked. Dont forget to accept the answer 🙂

strive
Influencer

In your case, you need to set TIME_PREFIX and MAX_TIMESTAMP_LOOKAHEAD. Check the props.conf documenattion
http://docs.splunk.com/Documentation/Splunk/6.1.1/Admin/Propsconf

TIME_PREFIX = foo|

MAX_TIMESTAMP_LOOKAHEAD = 12

Try these. Change the values as required.

strive
Influencer

Can you tell what will be there before |20131201. Is it one word or multiple words separated by |.

0 Karma

philip_wong
Communicator

"foo" is not fixed value.

I did try TIME_PREFIX = | and MAX_TIMESTAMP_LOOKAHEAD = 50 , still didn't work

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Data Management Digest – June 2026

Welcome to the June 2026 edition of Data Management Digest! This month’s update is short and sweet, with a ...

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...