Getting Data In

Edit of Time_format in props.conf on Cluster Master does not strike through

yAlff
Path Finder

Hello Community,

My Setup is 1 SearchHead, 1 Cluster Master, 2 Indexers and a bunch of Forwarders.
A logfile looks something like that:

<134>Aug 14 07:46:04 pm-1234

With pm-1234 as the host name. So Splunk does interpret the pm in the host name as past morning. In the example the interpreted time would be 19:46:04, but it it correctly 07:46:04 AM.

Yesterday, I added to the sourcetype in props.conf on Cluster Master following line:

TIME_FORMAT=%b %d %H:%M:%S

Followed by command

splunk apply cluster-bundle

But as I looked this morning, the new logfile entries are still interpreted false.

What did I forget?

Note: If I ingest the data and define another sourcetype for the data, where I set the TIME_FORMAT right, the timestamp is interpreted correctly; but this is not an option for me; it was only for testing. But if I edit this sourcetype in props.conf, I don't see that the change was successful.

0 Karma
1 Solution

yAlff
Path Finder

Ok, I had to use

TIME_PREFIX=<134>

now it works! Fine 🙂

View solution in original post

0 Karma

yAlff
Path Finder

Ok, I had to use

TIME_PREFIX=<134>

now it works! Fine 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...