Getting Data In

timestamp date in header, time in every event

evidales
Engager

Hi,
I have a log that the date part of the timestamp for every event only comes in the header and footer. I am able to parse the header, but that gives the same timestamp to every event.
Using a time_prefix: ([^,]+,){4} and the regex %H%M%S%2N to parse the last value as the time, it sometimes says that it is unable to parse it to a strptime and other times it parses it ok, even using the date of the header.

Log sample:

20181214,092255

9688,P088,I,01001,09441963

9688,P088,O,01001,09441984

9689,P088,I,01001,09442063

9689,P088,O,01001,09442077

9706,P015,I,05001,09442099

20181214,175510

Any help in ensuring a proper timestamp parsing in every occasion will be highly appreciated.

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...