Getting Data In

How can I get date from filename and time from inside logs.

dfigurello
Communicator

Hi Splunkers,

How can I get date from filename and time from inside the logs.
For example:

I have a file named LOG_09-10-2015.TXT and inside the log it contains something like:

23450001 value value value value
23450001 value value value value

I'd like to get the date from filename "09-10-15" and the time from file "23:45:00.01".

I tried many configurations but I didn't had suscess.

I changed the configuration at datetime.xml:
I put in "C:\Program Files\Splunk\etc\apps\search\local"

<define name="_masheddate3" extract="day, month, year">
<text><![CDATA[(?:^|source:).*?\d[0-9]-\d[0-9]-\d[0-9]]]></text>

(...)

<use name="_masheddate3"/>

My props.conf is:

[logs_test]

DATETIME_CONFIG=C:\Program Files\Splunk\etc\apps\search\local\datetime.xml

Let me know if you guys need more information,

Thanks for any suggestions.

Tags (2)

badrinath_itrs
Communicator

Hi,

Can you take a look into the below article .

http://blogs.splunk.com/2009/12/02/configure-splunk-to-pull-a-date-out-of-a-non-standard-filename/

Regards,
Badri

0 Karma

dfigurello
Communicator

Hi Badri,

I'd seen this topic and I followed all the steps but I didn't had success.
I am trying with Splunk 6.3 in Windows and Linux too.

Regards,

0 Karma

muebel
SplunkTrust
SplunkTrust

hmm, this is a good one heh

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Incident Response: Reduce Incident Recurrence with Automated Ticket Creation

Culture extends beyond work experience and coffee roast preferences on software engineering teams. Team ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 2)

Welcome to the "Splunk Classroom Chronicles" series, created to help curious, career-minded learners get ...