Getting Data In

set year to timestamp

sarit_s
Communicator

Hello

I'm getting logs from my customer and the timestamp there is day and month without year.
that case causes splunk to index the events with future dates
example:

12/31/20 11:59:59.000 PM Dec 31 23:59:59 csm kerne

how can i modify the date before indexing so i will see the correct timestamp ?

thanks

0 Karma

to4kawa
Ultra Champion

DATETIME_CONFIG = none at props.conf, and EXTRACT timestamp field and TRANSFORMS
make appropriate timestamp by INGEST_EVAL

0 Karma

PavelP
Motivator

Hello @sarit_s ,

actually 12/31/20 looks like a date (31 Dec 2020), just wrong one. I'd try to solve it on the log source side if possible.

0 Karma

sarit_s
Communicator

Hey
thanks for your answer

i cannot do anything with the source since it is third party costumer and he will not do any changes in the logs..

the year is the only wrong part

the link you sent me is not relevant since i don't have any part of the year and there it is pointing of situations with two digits of the year

there is no timestamp configuration in the sourcetype so i guess it is the default

thanks

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...

Developer Spotlight with Mika Borner

From Hackathon Winner to Enterprise Leader    Mika Borner, CEO and Founder of Datapunctum AG, has been ...