Getting Data In

What is the timestamp format for incoming sourcetype?

tomapatan
Contributor

Hi Everyone,

Data coming in from an API is using the _indextime as the _time field because the timestamp format that is being sent is not recognised by Splunk.

An example of the timestamp would look like this:

 

 

2016-06-21T01:18:51-07:00

 

 

OR

 

 

2018-02-16T06:34:31-08:00

 

 

 As you can see, an offset of -7 or -8 hours is being added to the time field.

The timestamp format we`re currently using for the sourcetype is:

 

 

%Y-%m-%dT%H:%M:%S%:z

 

 

This is no longer working after the sender made some changes to the timestamp, but I`m not entirely sure how to represent the new format.

Using Splunk Cloud.

 Any help would be greatly appreciated.

Toma.

Labels (1)
Tags (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

The timestamp specification does indeed look OK. The question is - are the timestamps more or less "current". Because if they aren't (are outside margins set by MAX_DAYS_AGO and MAX_DAYS_HENCE with additional constraints for MAX_DIFF_SECS_AGO and MAX_DIFF_SECS_HENCE), splunk will apply additional mechanics described in https://docs.splunk.com/Documentation/Splunk/Latest/Admin/Propsconf

0 Karma

tomapatan
Contributor

Good point,

The timestamps are quite old. What are the defaults for  MAX_DAYS_AGO and MAX_DAYS_HENCE as I cannot see them being defined in the sourcetype settings ?

Should I go ahead and define them ? Some of the data is older than 2000 days.

Many thanks.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The timestamp format is correct for the examples shown.

Perhaps the problem lies in the rest of the sourcetype configuration.

Please can you share some anonymised events and your sourcetype configuration.

0 Karma

tomapatan
Contributor

Hi,

I`ve added a sample event and sourcetype configurations, hope this is enough information.

1.png

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...