Splunk Search

Failed to parse timestamp for event

ml96
New Member

Splunk appeasrs to be failing to index the server.log for our ATG Joss instances. On the Splunk indexer the following warning can be found in the splunkd.log

I am new to using splunk, any help in resolving this would be great.

07-19-2010 08:35:10.835 WARN DateParserVerbose - Failed to parse timestamp for event. Context="source::D:\Deployments\Jboss\jboss-as\server\slot1\log\server.log|host::UAT80ATGCAD01V|JBOSS|remoteport::1071" Text=" at atg.servlet.pipeline.PipelineableServletImpl.passRequest(PipelineableServletImpl.java:116) at a..."

0 Karma

Stephen_Sorkin
Splunk Employee
Splunk Employee

Given the Text of this event, this means that the timestamper tried to find a timestamp in a line somewhere deep into a logged stack trace. It could have been caused by the forwarder disconnecting from the indexer. Is any data indexed from this source?

0 Karma

Lowell
Super Champion

Please "edit" you question and add a sample event to it. It sounds like some part of your indexing logic is incorrect (timestamp recognition, or event breaking) but there is no way to provide any specific help without a specific example.

0 Karma

ml96
New Member

I have been looking further into this problem. I am seeing many errors like below in the splunkd.log

07-17-2010 03:20:05.782 ERROR TcpInputProc - Error encountered for connection from host=uat80atgcad01v.comops.uk.tesco.org, ip=172.25.41.100. Winsock error 10054

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...