Splunk Enterprise

DateParserVerbose Failed to parse timestamp in first MAX_TIMESTAMP_LOOKAHEAD

hketer
Path Finder

 

Hi,

We have event with time field  Time=1650461136000
Props configuration parsing the time into 
_time: 2022-04-20 16:25:36
_indextime: 04/20/2022 16:22:43

[props]

TIME_PREFIX = ,\Time\=
TIME_FORMAT = %s%3N

That means the data ingest with future time.

With that being said, what are we missing? 
Why we still receive the warning  
"WARN Date ParserVerbose - Failed to parse timestamp in first MAX_TIMESTAMP_LOOKAHEAD (350) characters of event. Defaulting to timestamp of previous event"

Thank you!

 

Labels (2)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @hketer,

I suppose that you already checked the clocks of all the systems and that they are all aligned with an NTP server.

Then, could you share a sample of your logs with the wrong timestamp?

Ciao.

Giuseppe

0 Karma

hketer
Path Finder

Hi,

Thank you for the replay.

The Epochtime is the same as the _time
unfortunately I can't share the raw event.

 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @hketer,

sorry but I asked a different question: did you checked that the clock of the target server and the one of Indexers are aligned with an NTP server?

It seems that there a different time between them.

If you can't share events I cannot check the timestamp extraction, mask you data before sharing it.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...