Getting Data In

Splunk won't correctly recognize timestamp

pero1234
Path Finder

Why splunk won't correctly recognize this timestamp?

120129092233

my props.conf

TIME_FORMAT=%Y%m%d%H%M%S
TIME_PREFIX=^

example of source log:

120129092231;field1 field2  field3
120129092232;field1 field2  field3
120129092233;field1 field2  field3
Tags (2)
1 Solution

imrago
Contributor

try:

TIME_FORMAT=%y%m%d%H%M%S
TIME_PREFIX=^

View solution in original post

imrago
Contributor

try:

TIME_FORMAT=%y%m%d%H%M%S
TIME_PREFIX=^

pero1234
Path Finder

Works! Yes, y% is for year without century like in my log.
Splunk rocks!!

0 Karma

hedgehog
Explorer

Your time_Prefix stanza looks correct but I dont think you need the prefix. Not sure if the docs will shed some light but you can fine them here: http://docs.splunk.com/Documentation/Splunk/latest/Data/
ConfigureTimestampRecognition

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...