Getting Data In

Tricky parsing requirement

ssledzie
New Member

Say I fed a file into splunk that had a date field at the top.

Then after that, one event per line that contained a time offset from the aforementioned date field. Any way I could make splunk assign a timestamp from date+time offset to the event?

Tags (2)
0 Karma

lukejadamec
Super Champion

I'm gonna venture an educated guess - No, you cannot perform math on index time extractions.

However, you can math in a search. Once you get it the way you want it, you can create a macro so it can be called easily.

ssledzie
New Member

I'll check the doc thanks. In either case, the format would be something like:


DATE: 02/24/2014 11:00:00

0
5
10

In the above example 0,5, and 10 are offsets from the date header.

0 Karma

lukejadamec
Super Champion

Have you read this doc? http://docs.splunk.com/Documentation/Splunk/6.0.1/Data/HowSplunkextractstimestamps
According to that doc, if you can configure props.conf to recognize the 'date field' as an event of the same sourcetype, and pull the date as a date time, then all subsequent events would default to that 'date time' because the subsequent events of that same sourcetype do not have a valid 'date time'.

It is tough without seeing the data or log file structure.

0 Karma

ssledzie
New Member

That's fine. I'm willing to do that calculation at search time. But I still need the all the data on the event to do that.

0 Karma

Ayn
Legend

You'd still have to do math in order to add the start date and the offset. The timestamp processor doesn't have that kind of functionality.

0 Karma

ssledzie
New Member

What if I didn't do any math but appended the start date to every event? Is that possible?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...