Splunk Search

If year, month, day, hour, minute, and second are all different comma separated fields in my data, how do I assign the timestamp for a new sourcetype?

SilviaGebel
Path Finder

Hi,

I am trying to create a new sourcetype in order to get the timestamp right.
Year, month, day, hour, minute, second are different fields and comma separated, that's why Splunk does not recognize it as a timestamp.

This is my data:

2;2014;1;10;5;36;39;4;0;0;1;0;2;0;0;0;0;0;0;0;0;0;0;200;200,46301
3;2014;1;10;5;26;15;4;0;0;1;0;2;0;0;0;0;0;0;0;0;0;0;200;200,27934
4;2014;1;10;0;8;11;4;0;0;1;0;2;0;0;0;0;0;0;0;0;0;0;200;200,69374
5;2014;1;9;23;57;43;0;0;0;1;2;2;0;0;0;0;0;0;0;0;0;0;105;109,28964

The times i want to extract as timestamp are in this format:

2;%H;%m;%d;%H;%;M;%S;...
so for the first event: 10.01.2014 05:36:39 ( %Y.%m,%d %H:%M:%S ) as final format.

Where and what do I have to insert at advanced settings for timestamp configuration when creating a new sourcetype?

Thank's for your help!

Silvia

0 Karma
1 Solution

jeffland
SplunkTrust
SplunkTrust

You could define the timestamp for the sourcetype in your props.conf by adding the following stanza:

[Sourcetype_Name]
TIME_FORMAT = %Y;%m;%e;%k;%M;%S
MAX_TIMESTAMP_LOOKAHEAD = 25
category = Custom
disabled = false
pulldown_type = true

This will give you an option to explicitly select Sourcetype_Name in the list of sourcetypes you see while adding your data, so you can confirm it's working (I'm not sure about the strptime variables, whether they work like this with and without leading zeros). See here for more information.

View solution in original post

jeffland
SplunkTrust
SplunkTrust

You could define the timestamp for the sourcetype in your props.conf by adding the following stanza:

[Sourcetype_Name]
TIME_FORMAT = %Y;%m;%e;%k;%M;%S
MAX_TIMESTAMP_LOOKAHEAD = 25
category = Custom
disabled = false
pulldown_type = true

This will give you an option to explicitly select Sourcetype_Name in the list of sourcetypes you see while adding your data, so you can confirm it's working (I'm not sure about the strptime variables, whether they work like this with and without leading zeros). See here for more information.

SilviaGebel
Path Finder

Ok, thank you. But can you please tell me how to get to props.conf?

0 Karma

jeffland
SplunkTrust
SplunkTrust

For global settings, go to the props.conf in %splunk_home%/etc/system/local/.

0 Karma

SilviaGebel
Path Finder

and where do I find this? 😉

0 Karma

jeffland
SplunkTrust
SplunkTrust

Assuming you are on linux and have installed splunk in the default folder, that would be /opt/splunk/etc/system/local/.

0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...