Splunk Search

Train dates fails to recognize any date format

mrdaniel
Explorer

I have tried to get Splunk to recognize a new format of dates but im unable even to get the train date to understand the date, i only get : "Skipping unpromissing line" when running that on the logfile. The date and time is in the following format:

11032011 101305
11032011 101304

MMDDYYYY HHMMSS

I would need help to proceed to get Splunk to be able to recognize this date format.

Tags (1)
0 Karma

tgow
Splunk Employee
Splunk Employee

You will need to modify the props.conf with the following (assuming 24-hour clock) :

[yoursourcetype]
TIME_FORMAT = %m%d%Y %H%M%S

Here is a link to more information:

http://docs.splunk.com/Documentation/Splunk/4.2.3/Data/Configuretimestamprecognition

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...