Getting Data In

Time config incorrect

_joe
Contributor

This isn't so much a question as a comment. I found that time config to be incorrect. 

My logs start like this:
{"Time": "29 Jan 2025 03:16:30, PST",

The default timestring is expecting a 2 digit year.

 

%d %b %y %H:%M:%S, %Z

 

Prior to the update, Splunk was stil able to figure out the time but issed the timezone parameter. In other words, if your heavy forwarder has the same timezone as your zScaler logs you would probably be fine.

 

 

Labels (1)
0 Karma
1 Solution

_joe
Contributor

I updated it to a 4 digit year to match my logs. 

%d %b %Y %H:%M:%S, %Z

 

View solution in original post

0 Karma

_joe
Contributor

I updated it to a 4 digit year to match my logs. 

%d %b %Y %H:%M:%S, %Z

 

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...