Refine your search:

2
1

Hi,

How do I get splunk to show the date and time correctly based on the event?For example if I have the following event from oracle logs:

RETURNCODE=0,OS_PROCESS=1671350,EXTENDED_TIMESTAMP="22/07/10 12:55:50.251291 PM +08:00",TO_CHAR(EXTENDED_TIMESTAMP,'MM="07/22/2010 12:55:50",OS_USERNAME=,USERNAME=,USERHOST=,OBJ_NAME=,SCN=,ACTION=,TRANSACTIONID=,ACTION_NAME=""

Splunk is displaying the incorrect date as:
10/12/07 <-- translate to year 2007..
12:55:50.565 PM

Some events may translate with incorrect time as well.

Have tried using "DATETIME config=current" in props.conf,but still there is a time differences as the splunk and oracle server time is not in sync.

Any idea?

asked 22 Jul '10, 06:30

remy06's gravatar image

remy06
30718856
accept rate: 40%


One Answer:

remy you can try something like this:

[source::e:\logs\yourlogs\*]
MAX_TIMESTAMP_LOOKAHEAD = 75
TIME_FORMAT = %d/%m/%y %H:%M:%S

Here are the docs on this, read them for more knowledge on how to deal with this: Configure Timestamp Recognition

Cheers,
.gz

link

answered 22 Jul '10, 06:55

Genti's gravatar image

Genti ♦
4.0k7846
accept rate: 38%

Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×243
×114
×51

Asked: 22 Jul '10, 06:30

Seen: 2,372 times

Last updated: 22 Jul '10, 06:55

Copyright © 2005-2014 Splunk Inc. All rights reserved.