Getting Data In

Setting the timestamp of an event using part of the filename.

las
Contributor

Hi.

I have an application that runs once a day, just past midnight, and produces a file 20130628_000000_agent_statistics.csv, now since the file is produced at the 29th of June the modtime is 29. ‎juni ‎2013, ‏‎00:25:02.

Therefore when indexing this file, setting DATETIME_CONFIG = NONE is not an option, as it will revert to modtime.

Is the only option to get this type of file indexed right, to mess with datetime.xml, or are there other possibilities?

Kind regards

las

Tags (3)
0 Karma
1 Solution

las
Contributor

As this setup is batch orientated, I changed approach, and made a script to pull out the timestamp from the filename, and prepend it to the data.

Then it is a walk in the park to index the file correctly.

View solution in original post

0 Karma

las
Contributor

As this setup is batch orientated, I changed approach, and made a script to pull out the timestamp from the filename, and prepend it to the data.

Then it is a walk in the park to index the file correctly.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...