Getting Data In

Setting the timestamp of an event using part of the filename.

las
Contributor

Hi.

I have an application that runs once a day, just past midnight, and produces a file 20130628_000000_agent_statistics.csv, now since the file is produced at the 29th of June the modtime is 29. ‎juni ‎2013, ‏‎00:25:02.

Therefore when indexing this file, setting DATETIME_CONFIG = NONE is not an option, as it will revert to modtime.

Is the only option to get this type of file indexed right, to mess with datetime.xml, or are there other possibilities?

Kind regards

las

Tags (3)
0 Karma
1 Solution

las
Contributor

As this setup is batch orientated, I changed approach, and made a script to pull out the timestamp from the filename, and prepend it to the data.

Then it is a walk in the park to index the file correctly.

View solution in original post

0 Karma

las
Contributor

As this setup is batch orientated, I changed approach, and made a script to pull out the timestamp from the filename, and prepend it to the data.

Then it is a walk in the park to index the file correctly.

0 Karma
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Customers Increasingly Choose Splunk for Observability

For the second year in a row, Splunk was recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for ...