Hi, I'm having a weird problem with recognizing timestamps. The actual timestamp looks like this:
However, since the event itself contains the compilation time of the kernel (uname -a), Splunk will identify the date based on that, but will pick up the time from the timestamp. So the time of day changes, but the date is constantly 2012-01-20.
I've tried these settings in props.conf:
[my_sourcetype] TIME_PREFIX = ^ MAX_TIMESTAMP_LOOKAHEAD = 28
[my_sourcetype] TIME_PREFIX = \[ MAX_TIMESTAMP_LOOKAHEAD = 26
But the result is still the same.
Thanks. I was kind of hoping I could avoid using a regexp, since time formats may change with locales and such. Also, I don't really understand why the MAXTIMESTAMPLOOKAHEAD is ignored.
[2012-04-11 12:14:01+03:00] Linux hostname.domain.tld 2.6.18-274.18.1.el5 #1 SMP Fri Jan 20 15:11:18 EST 2012 x8664 x8664 x86_64 GNU/Linux
The log contains other events as well, but these all get indexed using the correct timestamp.