Getting Data In

Datetime.xml - extracting hour that does not exist

twkan
Splunk Employee
Splunk Employee

Hello all,

I have a series of logs that looks like this:

200312,111523  -> this means 20 March 2012, 11:15:23 am
200312,53344  -> this means 20 March 2012, 05:33:44 am (note that the first 0 is missing in the hour)
200312,1428 -> this means 20 March 2012, 00:14:28 am (note that the first two 00 are missing in the hour)

I have already written the datetime.xml to cater for the first two scenarios. But for the 3rd one where the hour is totally missing, how do I cater for this on my datetime.xml?

Has anyone managed to think of a way to 'substitue' 00 as the hour if it's missing from the logs itself?

Thanks for any insights.

0 Karma
1 Solution

twkan
Splunk Employee
Splunk Employee

Okay, decided to write a script to pad the time with zeros before being indexed by Splunk.

View solution in original post

0 Karma

twkan
Splunk Employee
Splunk Employee

Okay, decided to write a script to pad the time with zeros before being indexed by Splunk.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...