Getting Data In
Highlighted

TIME_FORMAT in props is not working

I have configured the TIME_FORMAT in props.conf as mentioned below.

[mySourceType]
INDEXEDEXTRACTIONS = csv
FIELD
DELIMITER = ,
SHOULDLINEMERGE = false
HEADER
FIELDLINENUMBER = 1
CHECKFORHEADER = true
NOBINARYCHECK = true
disabled = false
initCrcLength = 2048
CHARSET = AUTO
KVMODE = none
category = structured
description = Comma-separated value format. Set header and other settings in "Delimited Settings"
pulldown
type = 1
SEDCMD-replacespace = s/ //g
TIMESTAMP
FIELDS = "TimeField"
TIME_FORMAT = %Y-%m-%d %H:%M:%S
TZ = UTC

Monitoring CSV file in UF. This props is in indexer.

Example input data - 2019-08-13 07:15:00
2019-08-13 07:20:00

But after indexing _time is coming as 2019-08-13 07:00
2019-08-13 07:00

The Minute part is disappearing.

Please suggest some solution

Tags (2)
0 Karma
Highlighted

Re: TIME_FORMAT in props is not working

SplunkTrust
SplunkTrust

Put this settings in UF.

View solution in original post

Highlighted

Re: TIME_FORMAT in props is not working

Hey I tried again, it's working now. Thanks a lot. But , as per the documentation, time_format and all config should be there in Indexer and not in UF

0 Karma
Highlighted

Re: TIME_FORMAT in props is not working

Builder

What does your sample data look like? How many fields are in the CSV?

0 Karma
Highlighted

Re: TIME_FORMAT in props is not working

Sample data I had mentioned in the question (Example input data). There are around 50 fields

0 Karma
Highlighted

Re: TIME_FORMAT in props is not working

Builder

Can you give a whole row and the headers?

0 Karma
Highlighted

Re: TIME_FORMAT in props is not working

No, I can not do that. It's in secure environment

0 Karma
Highlighted

Re: TIME_FORMAT in props is not working

Contributor

Try TIME_FORMAT = %F %X

0 Karma
Highlighted

Re: TIME_FORMAT in props is not working

As per @somesoni2 suggestion, I put the props in UF and it is working fine now. Thanks.

0 Karma
Highlighted

Re: TIME_FORMAT in props is not working

Explorer

for reference,  

 

I put the props in UF and it is working fine now. Thanks

 

 Does this mean the directory of $SPLUNK_HOME/SplunkUniversalForwarder/default 
or something else? 

 

0 Karma