Getting Data In

How to reformat timestamp in SYSLOG _raw

dokaas_2
Communicator

SYSLOG often sends the timestamp in the older format (e.g. Jul 11 14:23:32).  Unfortunately, that format does not have a year or timezone.  I know that Splunk has logic to 'figure' it out, but I need to have it reformatted to the following:

  YYYY-MM-DDTHH:mm:ss<GMT offset>

 

Is there a way to accomplish this with INGEST_EVAL or other method?  If so how is it done?  This should change the _raw event(that is, this is not a search time question).  Kind of like a mask.

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @dokaas_2,

I know two solutions:

a pre-parsing script that reformat your logs before Splunk ingest them.

the SEDCMD command.

ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...