Getting Data In

Timestamp format

Vladimir
Path Finder

Hi,

I have log files which have timestamp format like

04/10/2012 07:50:09 - dd/mm/yyyy HH:MM:SS

but indexer thinks it's a mm/dd instead of dd/mm. Logs are monitored by forwarder which has a props.conf

[source::E:\Logging\] 
TIME_FORMAT = %d/%m/%Y %H:%M:%S

But still nothing changed. Data with timestamp, for example 04/10/2012 I can find for April, but not for October. Any suggestions?
Splunk forwarder version - 4.3.4, splunk indexer - 4.3

Tags (1)
1 Solution

echalex
Builder

The TIME_FORMAT needs to specified in your props.conf. Furthermore, it is relevant to the Splunk server that does the parsing. In other words, if your using a universal forwarder, you need to edit your props.conf on the indexer.

The alternative is to use a heavy forwarder to do parsing.

View solution in original post

echalex
Builder

The TIME_FORMAT needs to specified in your props.conf. Furthermore, it is relevant to the Splunk server that does the parsing. In other words, if your using a universal forwarder, you need to edit your props.conf on the indexer.

The alternative is to use a heavy forwarder to do parsing.

Vladimir
Path Finder

ok, got it. Will try to configure the indexer

0 Karma

Vladimir
Path Finder

and one more thing - this issue started from October only, for last months I didn't have such problem

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...