Getting Data In

Time config incorrect

_joe
Contributor

This isn't so much a question as a comment. I found that time config to be incorrect. 

My logs start like this:
{"Time": "29 Jan 2025 03:16:30, PST",

The default timestring is expecting a 2 digit year.

 

%d %b %y %H:%M:%S, %Z

 

Prior to the update, Splunk was stil able to figure out the time but issed the timezone parameter. In other words, if your heavy forwarder has the same timezone as your zScaler logs you would probably be fine.

 

 

Labels (1)
0 Karma
1 Solution

_joe
Contributor

I updated it to a 4 digit year to match my logs. 

%d %b %Y %H:%M:%S, %Z

 

View solution in original post

0 Karma

_joe
Contributor

I updated it to a 4 digit year to match my logs. 

%d %b %Y %H:%M:%S, %Z

 

0 Karma
Get Updates on the Splunk Community!

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...