Getting Data In

Timestamp on one event determines subsequent line events in RMAN backup

rasingh
Path Finder

I want to index log events from RMAN backup log. This log has a log event per line but each line may not have a timestamp. It looks like the example below:

Line event entry 1 at <TIMESTAMP1>
Line event entry 2
Line event entry 3
Line event entry 4 at <TIMESTAMP2>
Line event entry 5

How do I use the first read timestamp to be the timestamp for each subsequent event until a new timestamp is read?

Using the example above, TIMESTAMP1 would be the timestamp for Line event entries 1 thru 3 while TIMESTAMP2 would be the timestamp for Line event entries 4 & 5.

I think is the best way to handle the Oracle RMAN backup log unless someone has done better/differently before.

Tags (2)
0 Karma

rasingh
Path Finder

After testing this sample log file in Splunk, I found out Splunk already does that automatically.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...