Getting Data In

How to index data where the timestamp is not on every line or at the the beginning of a line?

omuelle1
Communicator

Hi,

I have an issue with data I am trying to index. I checked and the files are being monitored but I am still not seeing any data. I guess this has to with the way the data is organized.

For example not every line has a time stamp and the time stamp is not at the beginning of the line.

rum.rndcsalesforce.com - - [28/Nov/2016 07:28:03] "GET / HTTP/1.1" 200 -
LOG: -ZOMBIE: PkTaskMgmtS (exitcode:-11) pid:29053 status:starting
cleanup factories: ['TaskMgmtIFFactory:29053']

LOG: STARTED PkTaskMgmtS (#1) pid:27319 status:starting
-QUEUED: PkTaskMgmtS #Listeners:1
Started Factory TaskMgmtIFFactory via program PkTaskMgmtS
CLS Assertion failed: rc == 0, File /opt/manhattan64/coreservices/cls/5.0.11.rhel564/include/ClsLock.hpp, Line 578, TID 47196679497472, PID 22144

How would I go ahead and make my sourcetype to index this kinda data?

Thank you,

Oliver

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi omuelle1,
my suggest is to put an extraction of your logs in a text file and use the web guided function to add data.
In this way you can build your sourcetype and immediately verify if the timestamp is correctly acquired or not.
Bye.
Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi omuelle1,
my suggest is to put an extraction of your logs in a text file and use the web guided function to add data.
In this way you can build your sourcetype and immediately verify if the timestamp is correctly acquired or not.
Bye.
Giuseppe

omuelle1
Communicator

Thank you, I did this but it was still was indexing. Turns out the problem was on a different end:

File will not be read, seekptr checksum did not match. Last time we saw this initcrc, filename was different.  You may wish to use a CRC salt on this source.  Consult the documentation or file a support case online at http://www.splunk.com/page/submit_issue for more info.

Once I added crcSalt to the index.conf, the files were being indexed

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...