Getting Data In

Edit of Time_format in props.conf on Cluster Master does not strike through

yAlff
Path Finder

Hello Community,

My Setup is 1 SearchHead, 1 Cluster Master, 2 Indexers and a bunch of Forwarders.
A logfile looks something like that:

<134>Aug 14 07:46:04 pm-1234

With pm-1234 as the host name. So Splunk does interpret the pm in the host name as past morning. In the example the interpreted time would be 19:46:04, but it it correctly 07:46:04 AM.

Yesterday, I added to the sourcetype in props.conf on Cluster Master following line:

TIME_FORMAT=%b %d %H:%M:%S

Followed by command

splunk apply cluster-bundle

But as I looked this morning, the new logfile entries are still interpreted false.

What did I forget?

Note: If I ingest the data and define another sourcetype for the data, where I set the TIME_FORMAT right, the timestamp is interpreted correctly; but this is not an option for me; it was only for testing. But if I edit this sourcetype in props.conf, I don't see that the change was successful.

0 Karma
1 Solution

yAlff
Path Finder

Ok, I had to use

TIME_PREFIX=<134>

now it works! Fine 🙂

View solution in original post

0 Karma

yAlff
Path Finder

Ok, I had to use

TIME_PREFIX=<134>

now it works! Fine 🙂

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...