Splunk Enterprise

How to extract timestamp without year in log?

ricotries
Communicator

I am trying to ingest a new log and unfortunately, it doesn't include year or time zone as part of the message.

The timestamp in the messages is in the following format:

 

Jun 30 01:02:03 <msg>

 

I wrote the following props.conf settings to extract the timestamp in the message:

 

[new_sourcetype]
TIME_PREFIX = ^
MAX_TIMESTAMP_LOOKAHEAD = 15
TIME_FORMAT = %b %d %H:%M:%S

 

 I see the following warnings under splunkd.log:

 

06-30-2022 14:05:59.555 -0600 WARN  DateParserVerbose [1556614 merging] - The TIME_FORMAT specified is matching timestamps (Tue Jun  6 17:43:20 2023) outside of the acceptable time window. If this timestamp is correct, consider adjusting MAX_DAYS_AGO and MAX_DAYS_HENCE. Context: source=/path/to/log|host=UF01|new_sourcetype|230

 

 I'm confused where "(Tue Jun 6 17:43:20 2023)" is coming from because none of the logs have this string.

How do I approach this? I've thought about using transforms to write into the DEST_KEY "_time" but I read that any key starting with "_" is not indexed. This data is being received from a syslog server so I thought about modifying the data as it's being received. What are you recommendations?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...