Getting Data In

Event timestamp issue

newbiesplunk
Path Finder

Hi,
I encountered some event timestamp issue at the Data preview for Windows2007 SP2 stated below. When i using the input file and configure at some other server, the timestamp and event date is the correct. what went wrong and how to resolve it?

Timestamp                                 Event
9/25/01 4:31:20:000 AM             9/29/2014 12:42:00 AM ...........
9/25/01 4:33:50:000 AM             9/29/2014 12:43:33 AM .............

thks & rgds

Tags (1)
0 Karma

zillionlee
Path Finder

I think splunk doesn't pick the correct timestamp if as you say.Is it because the raw log has the same like string somewhere?
You can try to use the TIME_FORMAT property in $SPLUNK_HOME/etc/system/local/props.conf.
good luck 🙂

0 Karma
Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...