Getting Data In

Correct TIME_FORMAT for the following timestamp?

infomedix
New Member

Hello,
I'm having trouble extracting the following timestamp for one source, is there someone here that can recommend what values to put into the $SPLUNK_HOME/etc/system/default/local file under the TIME_FORMAT attribute?

Mon Oct 8 12:15:10 EST 2012:

That is currently being indexed as 10/9/12 4:15:10.000 AM when it should be 8/10/12 12:15:10 AM.

Thank you

Tags (1)
0 Karma

infomedix
New Member

I am still unsuccessful in configuring this, can anybody see anything that I am missing?

0 Karma

infomedix
New Member

I am looking at the newer ones, I fed new data into it after making the changes and restarting the service.

My gut feeling is that the props file is not being called...

0 Karma

Ayn
Legend

Are you looking for timestamps in new events or old ones? Events that have already been indexed will not be affected by this change, because they already have their timestamp set.

Otherwise check splunkd.log for messages related to strptime time extraction, to see what error it is throwing. You MIGHT need to include an extra ":" at the end in your TIME_FORMAT.

0 Karma

infomedix
New Member

Thanks Ayn, perhaps you can help me further, I placed the following in /opt/splunk/etc/system/local/props.conf:


[source::/directory/structure/logfile.log]

TIME_FORMAT = %a %b %e %H:%M:%S %Z %Y


Then restarted the service and fed more data into the log however it is still not recognising the timestamp. Is there something which I am doing wrong that you can see?

0 Karma

Ayn
Legend
%a %b %e %H:%M:%S %Z %Y
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...