Getting Data In

Setting the timestamp of an event using part of the filename.

las
Contributor

Hi.

I have an application that runs once a day, just past midnight, and produces a file 20130628_000000_agent_statistics.csv, now since the file is produced at the 29th of June the modtime is 29. ‎juni ‎2013, ‏‎00:25:02.

Therefore when indexing this file, setting DATETIME_CONFIG = NONE is not an option, as it will revert to modtime.

Is the only option to get this type of file indexed right, to mess with datetime.xml, or are there other possibilities?

Kind regards

las

Tags (3)
0 Karma
1 Solution

las
Contributor

As this setup is batch orientated, I changed approach, and made a script to pull out the timestamp from the filename, and prepend it to the data.

Then it is a walk in the park to index the file correctly.

View solution in original post

0 Karma

las
Contributor

As this setup is batch orientated, I changed approach, and made a script to pull out the timestamp from the filename, and prepend it to the data.

Then it is a walk in the park to index the file correctly.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...