Splunk Enterprise

Why is Splunk is changing day for month?

ptlemos
Engager

Hi,

 

i have an edge server with splunk forward to ship log file to indexer.

The log is being indexed but splunk is changing days for months.

The events start with the example 

17:00:16,965;06-12-2022 17:00:16.740;10.129.150.83;

This event is from 6 of december but is indexed as 12 of June.

ptlemos_0-1670944430389.png

ptlemos_1-1670944457848.png

The time field is ok but _time not.

I add props.conf at app/local on edge server with the following configs but did not resolve

[mbe-cdr]
TIME_PREFIX = \d+:\d+:\d+\,\d+\;
TIME_FORMAT = %d-%m-%Y %H:%M:%S.%Q

 

Thanks in advance

 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The TIME_FORMAT setting looks correct, but for it to be effective it must be on the first Splunk Indexer or Heavy Forwarder that processes the data.  It can't hurt to put the props.conf settings in both places.  Universal Forwarders will ignore TIME_FORMAT.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

ptlemos
Engager

Thanks for the input, configure props.conf on the indexer and solve the problem.

richgalloway
SplunkTrust
SplunkTrust

The TIME_FORMAT setting looks correct, but for it to be effective it must be on the first Splunk Indexer or Heavy Forwarder that processes the data.  It can't hurt to put the props.conf settings in both places.  Universal Forwarders will ignore TIME_FORMAT.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...