Splunk Search
Highlighted

Strptime statement not extracting date/time

Path Finder

I've been trying to import the data into splunk and have been unable to get the time/date to work. Included is a screenshot. Any help is appreciatedalt text

0 Karma
Highlighted

Re: Strptime statement not extracting date/time

Builder

Did you try Auto Extraction?

0 Karma
Highlighted

Re: Strptime statement not extracting date/time

Path Finder

yes. no luck.

0 Karma
Highlighted

Re: Strptime statement not extracting date/time

SplunkTrust
SplunkTrust

The screen shot is not visible. Try pasting some sample data as well as the strptime() strings you've tried.

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Highlighted

Re: Strptime statement not extracting date/time

Path Finder

Here it is

0 Karma
Highlighted

Re: Strptime statement not extracting date/time

Path Finder

The time I'm trying to base it on is the Start Date.

0 Karma
Highlighted

Re: Strptime statement not extracting date/time

SplunkTrust
SplunkTrust

I don't see a Start Date. There is no screen shot or sample data.

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Highlighted

Re: Strptime statement not extracting date/time

SplunkTrust
SplunkTrust

Could you provide the other configuration that you're using here, is this a structured format file (PSV/CSV/TSV etc)?

Highlighted

Re: Strptime statement not extracting date/time

Path Finder

its a csv.

0 Karma
Highlighted

Re: Strptime statement not extracting date/time

SplunkTrust
SplunkTrust

Well, I did some testing with sample CSV data and looks like the time format is the issue. The TIME format should be exactly same as what's in the "Start Date" field. So try timestamp format as "%m/%d/%Y %H:%M"

0 Karma