Getting Data In

How to edit props.conf so Splunk will recognize a month's time format when the month is in all caps?

splk5000
New Member

Seeking help with TIME_FORMAT in props.conf.

I'm trying to get Splunk to recognize a time format in the form of "JAN 3 2016". Seems simple enough, but none of the strptime fields address the month field with all caps. For example if it was instead "Jan 3 2016" where only the "J" is capitalized I could use TIME_FORMAT = "%b %e %Y". But because the month is in the format of "JAN" the %b does not recognize the month. Recommendations on how to set TIME_FORMAT?

0 Karma
1 Solution

niketn
Legend

Would you be able to give the complete date string for timestamp? Also few sample events?

For the following data strptime timestamp format %b %d %Y %H:%M:%S.%3N worked for me:

JAN 3 2016 20:17:13.000, my test data line 1
JAN 3 2016 20:17:14.000, my test data line 2
JAN 3 2016 20:17:15.000, my test data line 3

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

cdoebert
Path Finder

strptime() is case-insensitive, so there might be something else at fault.

0 Karma

splk5000
New Member

Thank you!

0 Karma

cdoebert
Path Finder

You're welcome, but we can help you get to the bottom of the problem!

Like niketnilay said, if we had a complete date string or a few sample events, we can track down what might really be going on.

0 Karma

niketn
Legend

Would you be able to give the complete date string for timestamp? Also few sample events?

For the following data strptime timestamp format %b %d %Y %H:%M:%S.%3N worked for me:

JAN 3 2016 20:17:13.000, my test data line 1
JAN 3 2016 20:17:14.000, my test data line 2
JAN 3 2016 20:17:15.000, my test data line 3

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

niketn
Legend

@splk5000 I have converted my comment to answer since %d resolved the issue in this case.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

splk5000
New Member

It seems that %b wasn't the variable causing the trouble; the discrepancy was using the %e instead of %d. When I used %d it properly extracted the date.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...