Getting Data In

Time stamp on custom imported file @Please Help@

j666gak
Communicator

Hello,

I have never done an import on Splunk, so i'm sorry if this has been asked although I can't find it if it has.

I am trying to import a web usage log that is in the following format(below). I have tried doing a custom import as it didn't fit any of the preset ones, although when looking in Splunk after indexing the time stamp is completely wrong.

Tue 03 Jan 2012 10:25:57 AM CET

Considerations -
* Don't need the day "Tue"
* Month is not a numerical value ie 01 for Jan
* Not in 24hr format so shows AM/PM
* Time on the log was taken in CET, is it possible to convert to GMT London? same as Splunk server

I really need help on how to configure this please. If anybody can help I would be really greatful, thanks for your time.

Cheers
Guy

0 Karma

lguinn2
Legend

BTW, you can tell Splunk that the input is in one of the following known web log formats:
access_combined (Apache)
access_combined_wcookie (Apache)
iis (Microsoft IIS)

You can find this by choosing More Options, and then setting the value for sourcetype (you will need to select Manual instead of Automatic) to do this.

0 Karma

MarioM
Motivator
0 Karma

lguinn2
Legend

Splunk is usually very good at parsing timestamps in exactly this format. So, can you show us a few complete events? (anonymizing any private stuff of course) I suspect that Splunk is just confused about where to find the timestamp within the event, not with the format itself.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...