Splunk Enterprise

Why is Splunk is changing day for month?

ptlemos
Engager

Hi,

 

i have an edge server with splunk forward to ship log file to indexer.

The log is being indexed but splunk is changing days for months.

The events start with the example 

17:00:16,965;06-12-2022 17:00:16.740;10.129.150.83;

This event is from 6 of december but is indexed as 12 of June.

ptlemos_0-1670944430389.png

ptlemos_1-1670944457848.png

The time field is ok but _time not.

I add props.conf at app/local on edge server with the following configs but did not resolve

[mbe-cdr]
TIME_PREFIX = \d+:\d+:\d+\,\d+\;
TIME_FORMAT = %d-%m-%Y %H:%M:%S.%Q

 

Thanks in advance

 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The TIME_FORMAT setting looks correct, but for it to be effective it must be on the first Splunk Indexer or Heavy Forwarder that processes the data.  It can't hurt to put the props.conf settings in both places.  Universal Forwarders will ignore TIME_FORMAT.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

ptlemos
Engager

Thanks for the input, configure props.conf on the indexer and solve the problem.

richgalloway
SplunkTrust
SplunkTrust

The TIME_FORMAT setting looks correct, but for it to be effective it must be on the first Splunk Indexer or Heavy Forwarder that processes the data.  It can't hurt to put the props.conf settings in both places.  Universal Forwarders will ignore TIME_FORMAT.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...