Getting Data In

Event timestamp issue

newbiesplunk
Path Finder

Hi,
I encountered some event timestamp issue at the Data preview for Windows2007 SP2 stated below. When i using the input file and configure at some other server, the timestamp and event date is the correct. what went wrong and how to resolve it?

Timestamp                                 Event
9/25/01 4:31:20:000 AM             9/29/2014 12:42:00 AM ...........
9/25/01 4:33:50:000 AM             9/29/2014 12:43:33 AM .............

thks & rgds

Tags (1)
0 Karma

zillionlee
Path Finder

I think splunk doesn't pick the correct timestamp if as you say.Is it because the raw log has the same like string somewhere?
You can try to use the TIME_FORMAT property in $SPLUNK_HOME/etc/system/local/props.conf.
good luck 🙂

0 Karma
Get Updates on the Splunk Community!

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...