Getting Data In

Time stamp on custom imported file @Please Help@

j666gak
Communicator

Hello,

I have never done an import on Splunk, so i'm sorry if this has been asked although I can't find it if it has.

I am trying to import a web usage log that is in the following format(below). I have tried doing a custom import as it didn't fit any of the preset ones, although when looking in Splunk after indexing the time stamp is completely wrong.

Tue 03 Jan 2012 10:25:57 AM CET

Considerations -
* Don't need the day "Tue"
* Month is not a numerical value ie 01 for Jan
* Not in 24hr format so shows AM/PM
* Time on the log was taken in CET, is it possible to convert to GMT London? same as Splunk server

I really need help on how to configure this please. If anybody can help I would be really greatful, thanks for your time.

Cheers
Guy

0 Karma

lguinn2
Legend

BTW, you can tell Splunk that the input is in one of the following known web log formats:
access_combined (Apache)
access_combined_wcookie (Apache)
iis (Microsoft IIS)

You can find this by choosing More Options, and then setting the value for sourcetype (you will need to select Manual instead of Automatic) to do this.

0 Karma

MarioM
Motivator
0 Karma

lguinn2
Legend

Splunk is usually very good at parsing timestamps in exactly this format. So, can you show us a few complete events? (anonymizing any private stuff of course) I suspect that Splunk is just confused about where to find the timestamp within the event, not with the format itself.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...