Splunk Search

Splunk not recognizing the date format

oliverkunert
New Member

Splunk is not recognizing the date and time of my data correctly.
My data is in the common log format. An example of a line would be:

192.168.2.1 Logname Username [02/Aug/2002:20:16:59 -0700] "GET /img/pic.jpg HTTP/1.0" 200 56812

Where 02/Aug/2002 would be the date, 20:16:59 the time and -0700 the timezone.
It has a unique sourcetype that is correctly assigned.
When searching for the data the _time field shows incorrect and semi-random values.

My props.conf:

[mysourcetype]
TIME_FORMAT=[%d/%b/%Y:%H:%M:%S %z]
TIME_PREFIX=^

The time format shows the correct regex in Splunk Web under Sourcetypes, so my props.conf gets loaded.

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Try these props.conf settings.

[mysourcetype]
TIME_FORMAT=%d/%b/%Y:%H:%M:%S %z
TIME_PREFIX=\[
---
If this reply helps you, Karma would be appreciated.

View solution in original post

sbbadri
Motivator

try below,

[mysourcetype]
TIME_FORMAT=\[%d/%b/%Y:%H:%M:%S %z\]
TIME_PREFIX=^\d+\.\d+\.+d\.\d+\s\S+\s\S+\s\[

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It won't work with \[ in both TIME_PREFIX and TIME_FORMAT.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Try these props.conf settings.

[mysourcetype]
TIME_FORMAT=%d/%b/%Y:%H:%M:%S %z
TIME_PREFIX=\[
---
If this reply helps you, Karma would be appreciated.

oliverkunert
New Member

After I used your configuration the problem still persisted. After removing the date from extracted fields for the search it worked.

0 Karma

adonio
Ultra Champion

try and remove the square brackets around your time format

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...