Splunk Enterprise

How to extract timestamp without year in log?

ricotries
Communicator

I am trying to ingest a new log and unfortunately, it doesn't include year or time zone as part of the message.

The timestamp in the messages is in the following format:

 

Jun 30 01:02:03 <msg>

 

I wrote the following props.conf settings to extract the timestamp in the message:

 

[new_sourcetype]
TIME_PREFIX = ^
MAX_TIMESTAMP_LOOKAHEAD = 15
TIME_FORMAT = %b %d %H:%M:%S

 

 I see the following warnings under splunkd.log:

 

06-30-2022 14:05:59.555 -0600 WARN  DateParserVerbose [1556614 merging] - The TIME_FORMAT specified is matching timestamps (Tue Jun  6 17:43:20 2023) outside of the acceptable time window. If this timestamp is correct, consider adjusting MAX_DAYS_AGO and MAX_DAYS_HENCE. Context: source=/path/to/log|host=UF01|new_sourcetype|230

 

 I'm confused where "(Tue Jun 6 17:43:20 2023)" is coming from because none of the logs have this string.

How do I approach this? I've thought about using transforms to write into the DEST_KEY "_time" but I read that any key starting with "_" is not indexed. This data is being received from a syslog server so I thought about modifying the data as it's being received. What are you recommendations?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...