Here is the file name and my datetime.xml config. When I apply this and try to import the data, Splunk gets stuck in preview and never shows the data.
Thanks in advance for the assist!
<datetime> <define name="_masheddate3" extract="month, day, year"> <text><![CDATA[(?:^|source::|source:).*?ADESS_FANALL_(\d)(\d)(20\d)]]></text> </define> <datePatterns> <use name="_masheddate3"/> </datePatterns> </datetime>
I have followed same steps which you have mentioned in comment but am not getting any date extraction. Could you please help me
copy datetime.xml to specific directory. cp -p /home/splunk/etc/datetime.xml /home/splunk/etc/system/local/my_datetime.xml configure props.conf [mysourcetype] DATETIME_CONFIG = /etc/system/local/my_datetime.xml ... Put your datetime configuration to my_datetime.xml (I didn't remove anything from my_datetime.xml) restart Splunk and monitor file
Thanks in Adavance
Did you remove all of configuration from datetime.xml? Why don't you copy datetime.xml from /etc to your directory?
I got the same situation and I resolved that like below.
copy datetime.xml to specific directory.
cp -p /home/splunk/etc/datetime.xml /home/splunk/etc/system/local/my_datetime.xml
DATETIMECONFIG = /etc/system/local/mydatetime.xml
Put your datetime configuration to mydatetime.xml (I didn't remove anything from mydatetime.xml)
restart Splunk and monitor file
At that moment,I saw my test file name of ADESSFANALL0108201401172014195441.csv was indexed with expected timestamp. (14/01/08 xx:xx:xx.xxx)