Getting Data In

Time stamp on custom imported file @Please Help@

j666gak
Communicator

Hello,

I have never done an import on Splunk, so i'm sorry if this has been asked although I can't find it if it has.

I am trying to import a web usage log that is in the following format(below). I have tried doing a custom import as it didn't fit any of the preset ones, although when looking in Splunk after indexing the time stamp is completely wrong.

Tue 03 Jan 2012 10:25:57 AM CET

Considerations -
* Don't need the day "Tue"
* Month is not a numerical value ie 01 for Jan
* Not in 24hr format so shows AM/PM
* Time on the log was taken in CET, is it possible to convert to GMT London? same as Splunk server

I really need help on how to configure this please. If anybody can help I would be really greatful, thanks for your time.

Cheers
Guy

0 Karma

lguinn2
Legend

BTW, you can tell Splunk that the input is in one of the following known web log formats:
access_combined (Apache)
access_combined_wcookie (Apache)
iis (Microsoft IIS)

You can find this by choosing More Options, and then setting the value for sourcetype (you will need to select Manual instead of Automatic) to do this.

0 Karma

MarioM
Motivator
0 Karma

lguinn2
Legend

Splunk is usually very good at parsing timestamps in exactly this format. So, can you show us a few complete events? (anonymizing any private stuff of course) I suspect that Splunk is just confused about where to find the timestamp within the event, not with the format itself.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...