Getting Data In

Extracting event date from file path

swdonline
Path Finder

hello all,

I have a set of log files being created in a directory structure as:
/data/hostname/year/month/day/logfile

I understand that I can use the host_segment command to extract the field. I cannot, however, seem to find a way for splunk to automatically extract the date from this path. Any recommendations would be appreciated.

0 Karma

gelica
Communicator

Hi,
Did you ever find a way to do this? 🙂

0 Karma

n0b1ta
New Member

I'm having the same proble,. I'm quite new to splunk.
Can anyone please describe more details ?
How can I setup dynamic directories based on timestamp?

Thanks

0 Karma

Ayn
Legend

While I haven't tried this is a setup of my own, according to the documentation Splunk should be doing this automatically if it cannot find a timestamp for events in a file.

See the precedence rules for how Splunk assigns timestamps to events here: http://docs.splunk.com/Documentation/Splunk/latest/Data/HowSplunkextractstimestamps

swdonline
Path Finder

Thanks Ayn. I did indeed check the docs prior to posting and what I think is the problem is "4. If no events in a source have a date, look in the source (or file) name (Must have time in the event)." Specifically, my events have no timestamps. It's just a summary of items for a 24 hour period. So it seems to be defaulting to #5 or #6. Is there a workaround to force date extraction without timestamps? Or a way to force a timestamp of 00:00 without scripting input?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...