Getting Data In

Event timestamp issue

newbiesplunk
Path Finder

Hi,
I encountered some event timestamp issue at the Data preview for Windows2007 SP2 stated below. When i using the input file and configure at some other server, the timestamp and event date is the correct. what went wrong and how to resolve it?

Timestamp                                 Event
9/25/01 4:31:20:000 AM             9/29/2014 12:42:00 AM ...........
9/25/01 4:33:50:000 AM             9/29/2014 12:43:33 AM .............

thks & rgds

Tags (1)
0 Karma

zillionlee
Path Finder

I think splunk doesn't pick the correct timestamp if as you say.Is it because the raw log has the same like string somewhere?
You can try to use the TIME_FORMAT property in $SPLUNK_HOME/etc/system/local/props.conf.
good luck 🙂

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...