My event have separate date and time fields on separate lines. E.g.
Date: 29 April 2013
Is it possible to configure Splunk to automatically extract timestamps for these events, piecing together the date and time as necessary?
Splunk is fairly good at interpreting timestamps by itself. You could try to index a log file and see how well it performs. Two things, though;
1) ensure that you have correct linebreaking, since splunk will normally break events when on the line where it encounters a timestamp. So if you have some lines before the timestamp that are part of the event, you may need to get explicit with some
props.conf settings (either a `SHOULDLINEMERGE=true / MUSTBREAK.., BREAKONLY..
combo, orSHOULDLINEMERGE=false / LINEBREAKER
combo. See the docs forprops.conf` for this.
2) You'll probably need to adjust the
MAX_TIMESTAMP_LOOKAHEAD to a higher number than the default 150.
See this (and the following) page(s);
Hope this helps,