Getting Data In

Splunk won't correctly recognize timestamp

pero1234
Path Finder

Why splunk won't correctly recognize this timestamp?

120129092233

my props.conf

TIME_FORMAT=%Y%m%d%H%M%S
TIME_PREFIX=^

example of source log:

120129092231;field1 field2  field3
120129092232;field1 field2  field3
120129092233;field1 field2  field3
Tags (2)
1 Solution

imrago
Contributor

try:

TIME_FORMAT=%y%m%d%H%M%S
TIME_PREFIX=^

View solution in original post

imrago
Contributor

try:

TIME_FORMAT=%y%m%d%H%M%S
TIME_PREFIX=^

pero1234
Path Finder

Works! Yes, y% is for year without century like in my log.
Splunk rocks!!

0 Karma

hedgehog
Explorer

Your time_Prefix stanza looks correct but I dont think you need the prefix. Not sure if the docs will shed some light but you can fine them here: http://docs.splunk.com/Documentation/Splunk/latest/Data/
ConfigureTimestampRecognition

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...