Splunk Search

Train dates fails to recognize any date format

mrdaniel
Explorer

I have tried to get Splunk to recognize a new format of dates but im unable even to get the train date to understand the date, i only get : "Skipping unpromissing line" when running that on the logfile. The date and time is in the following format:

11032011 101305
11032011 101304

MMDDYYYY HHMMSS

I would need help to proceed to get Splunk to be able to recognize this date format.

Tags (1)
0 Karma

tgow
Splunk Employee
Splunk Employee

You will need to modify the props.conf with the following (assuming 24-hour clock) :

[yoursourcetype]
TIME_FORMAT = %m%d%Y %H%M%S

Here is a link to more information:

http://docs.splunk.com/Documentation/Splunk/4.2.3/Data/Configuretimestamprecognition

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...