Getting Data In

timestamp event

gabriel94
New Member

Hi,

I have already a date field on my CSV file but it isn't recognize.

How I can help splunk to recognize this field to use as a timestamp ?

My file :
;"WIZARD_OR_SEARCH_NAME";"IDENTIFIER";"STATUS";"TEXT";"DATE"
;"NULL";"NULL";"NULL";"ok";"NULL";"2011-10-19 04:39:14"

Tags (3)
0 Karma

lguinn2
Legend

There are many settings available in Splunk for setting timestamps. For your case: First, identify the props.conf that you need to edit. If you aren't sure, you can create $SPLUNK_HOME/etc/system/local/props.conf. Try

[source::/pathtoyoursource]
MAX_TIMESTAMP_LOOKAHEAD = 0

By default, Splunk expects to see the timestamp in the first 150 characters of the event. This setting disables that, so Splunk will look all the way to the end of the event. There are other settings as well. For example, if you are trying to add older data, you might need to set MAX_DAYS_AGO.

You might also want to add

SHOULD_LINEMERGE=false

if your CSV file is one line per event. This will speed up processing of your input, and may improve timestamp recognition.

BTW, if you have control of the format of the CSV file, you could move the timestamp so it is the first column of the file. Splunk would process the input more efficiently.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...