Getting Data In

Event timestamp issue

newbiesplunk
Path Finder

Hi,
I encountered some event timestamp issue at the Data preview for Windows2007 SP2 stated below. When i using the input file and configure at some other server, the timestamp and event date is the correct. what went wrong and how to resolve it?

Timestamp                                 Event
9/25/01 4:31:20:000 AM             9/29/2014 12:42:00 AM ...........
9/25/01 4:33:50:000 AM             9/29/2014 12:43:33 AM .............

thks & rgds

Tags (1)
0 Karma

zillionlee
Path Finder

I think splunk doesn't pick the correct timestamp if as you say.Is it because the raw log has the same like string somewhere?
You can try to use the TIME_FORMAT property in $SPLUNK_HOME/etc/system/local/props.conf.
good luck 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

test 2

test 222222

test

test

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...