Getting Data In
Highlighted

could not use strptime to parse timestamp - csv file

Path Finder

Having issue importing csv, the Data format looks like this in CSV:

,Transactions,,,,,,,,
,XXXX XXXX XXXX 7282: ,,30/10/2014 to 30/04/2015,,,,,,
,,,,,,,,,
,Date,,Description,,Money in,Money Out,Balance,,
,,,,,,,,,
,30/04/2015,,"CARD PAYMENT TO SPOTIFY SPOTIFY PREMIU,9.99 GBP, RATE 1.00/GBP ON 28-04-2015",,,9.99,"1,579.75",,
,29/04/2015,,"CARD PAYMENT TO THE SOUTHERN CO-OP,4.95 GBP, RATE 1.00/GBP ON 27-04-2015",,,4.95,"1,589.74",,
,28/04/2015,,"CARD PAYMENT TO HOMEBASE LTD 107,34.99 GBP, RATE 1.00/GBP ON 25-04-2015",,,34.99,"1,594.69",,

Im using TIME_FORMAT = %d/%m/%y and im seeing error:
could not use the strptime to parse the time stamp from ",,"

Thanks!

0 Karma
Highlighted

Re: could not use strptime to parse timestamp - csv file

Path Finder

correction im using TIME_FORMAT = %d/%m/%Y

0 Karma
Highlighted

Re: could not use strptime to parse timestamp - csv file

Path Finder

Anyone help on this?

0 Karma
Highlighted

Re: could not use strptime to parse timestamp - csv file

Builder

Can you please verify the CSV? Concecutive ,, in the csv headers might be causing the issue.

Thanks!!

0 Karma
Highlighted

Re: could not use strptime to parse timestamp - csv file

Path Finder

Yes if i remove those ,, it works no problem. But i dont want to do that each time. How can i tell splunk to ignore it?

0 Karma
Highlighted

Re: could not use strptime to parse timestamp - csv file

Builder
0 Karma
Highlighted

Re: could not use strptime to parse timestamp - csv file

Builder

Is it working for you?

Thanks!!

0 Karma
Highlighted

Re: could not use strptime to parse timestamp - csv file

Splunk Employee
Splunk Employee

Try setting the TIME_PREFIX since there is a , in front of the date. This should work:

$SPLUNK_HOME/etc/system/local/props.conf on indexers:

[yoursourcetype]
TIME
FORMAT=%d/%m/%Y
TIMEPREFIX=,
MAX
TIMESTAMPLOOKAHEAD=10
SHOULD
LINEMERGE=false
NOBINARYCHECK=true

0 Karma