Getting Data In

Setting the timestamp of an event using part of the filename.

las
Contributor

Hi.

I have an application that runs once a day, just past midnight, and produces a file 20130628_000000_agent_statistics.csv, now since the file is produced at the 29th of June the modtime is 29. ‎juni ‎2013, ‏‎00:25:02.

Therefore when indexing this file, setting DATETIME_CONFIG = NONE is not an option, as it will revert to modtime.

Is the only option to get this type of file indexed right, to mess with datetime.xml, or are there other possibilities?

Kind regards

las

Tags (3)
0 Karma
1 Solution

las
Contributor

As this setup is batch orientated, I changed approach, and made a script to pull out the timestamp from the filename, and prepend it to the data.

Then it is a walk in the park to index the file correctly.

View solution in original post

0 Karma

las
Contributor

As this setup is batch orientated, I changed approach, and made a script to pull out the timestamp from the filename, and prepend it to the data.

Then it is a walk in the park to index the file correctly.

0 Karma
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...