Splunk Enterprise

Why is Splunk is changing day for month?

ptlemos
Engager

Hi,

 

i have an edge server with splunk forward to ship log file to indexer.

The log is being indexed but splunk is changing days for months.

The events start with the example 

17:00:16,965;06-12-2022 17:00:16.740;10.129.150.83;

This event is from 6 of december but is indexed as 12 of June.

ptlemos_0-1670944430389.png

ptlemos_1-1670944457848.png

The time field is ok but _time not.

I add props.conf at app/local on edge server with the following configs but did not resolve

[mbe-cdr]
TIME_PREFIX = \d+:\d+:\d+\,\d+\;
TIME_FORMAT = %d-%m-%Y %H:%M:%S.%Q

 

Thanks in advance

 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The TIME_FORMAT setting looks correct, but for it to be effective it must be on the first Splunk Indexer or Heavy Forwarder that processes the data.  It can't hurt to put the props.conf settings in both places.  Universal Forwarders will ignore TIME_FORMAT.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

ptlemos
Engager

Thanks for the input, configure props.conf on the indexer and solve the problem.

richgalloway
SplunkTrust
SplunkTrust

The TIME_FORMAT setting looks correct, but for it to be effective it must be on the first Splunk Indexer or Heavy Forwarder that processes the data.  It can't hurt to put the props.conf settings in both places.  Universal Forwarders will ignore TIME_FORMAT.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...