Getting Data In

Timestamp parsing from filename

jackin
Path Finder

Hi

I want to write the props for below logs.

Actually the logs are coming with no timestamp and the file name having the timestamp. 

These are the logs:

Message Is: https POST failed: . Status Is: Ok

Message Is: https POST successful: 200. Status Is: Ok

Changed .Pac File to http://liteway.prog2.com/proxyins/proxy_client.oac

Unable to change .Pac File to http://liteway.prog2.com/proxyins/proxy_client.oac

File name coming like 

zscalerhttp_2023-01-09-18-03-25

Can anyone help to write the props for this logs.. 

 

Labels (2)
0 Karma

jackin
Path Finder

Yes @PickleRick 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OK. There is no setting that would allow you to extract timestamp from filename or path directly. The only way I see is to use a INGEST_EVAL functionality. See https://conf.splunk.com/files/2020/slides/PLA1154C.pdf (slide 28 onwards)

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Let me get this straight - you have a separate file per each event?

0 Karma

jackin
Path Finder

Yes @PickleRick 

0 Karma
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...