Hi all!
I have a problem with my log. Some events have only one timestamp, some have two - as in this example : http://docs.splunk.com/Documentation/Splunk/6.2.1/Data/Configure...
Hi,
I have two different type log files using in Splunk and I do not have any timestamp issue with the first one (date/month/year hout:minute:second). But the other log file timestamp structure i...
Hi,
I have a problem with the Splunk timestamp.
I know that when you have a problem with timestamp, you can modify this 2 ways:
1. Add data and modify the timestamp during the steps of a...
Hi,
I am trying Splunk and try to evaluate it as a tool for managing the logs of our in-house applications. I am uploading a file with thousands of lines like the following ones (2 sample lines): ...
Hi
Until now, I had comma separated text inputs from many of my sources. Using props.conf, I could define the timestamp (e.g. which position and look ahead etc).
However, I anticipate JSON d...
Hi Folks,
Please anyone help me to configure event linebreaking and timestamprecognition for below format logs.
sample logs:
trc file: "dev_w0", trc level: 1, release: "742"
*
* A...
We have a firewall sending events to a Splunk indexer via syslog, so we have a section of our inputs.conf file like this:
[tcp://<port over which syslog data is sent>]
connection_host = dns...
...ation for this?
The logs currently use this variation: 2018-03-02T17:02:09.335Z
What is the recommended way to configuretimestamprecognition for the above sample?
...elated TIME_PREFIX . Perhaps I'm just nitpicking, splitting hairs. Moving on...
From the Splunk docs topic "Configuretimestamprecognition", with my additional highlighting:
If you don't s...
...015;2;11;11;25;40;0;0;0;2;1;2;0;0;0;0;0;0;0;0;0;0;105;103.19698;-1.7171659;7.9590001;72.3592;129.99324;101.17622;24037.746;397.58435;6;36.18;105.37886
The auto time stamp recognition does not work and a...