Splunk is struggling with this log format. any advise on how to get splunk to read the time stamp with day of the week included?:
Thu Mar 06 08:08:07 PST 2014 LogSource=SERVICE ExperimentId=2897 MessageCount=1
Thu Mar 06 08:08:07 PST 2014 LogSource=SERVICE ExperimentId=3112 MessageCount=4
Thu Mar 06 08:08:07 PST 2014 LogSource=SERVICE ExperimentId=3391 MessageCount=2
Thu Mar 06 08:08:07 PST 2014 LogSource=SERVICE ExperimentId=3594 MessageCount=7
Thu Mar 06 08:08:07 PST 2014 LogSource=SERVICE ExperimentId=2634 MessageCount=406
Splunk should be able to parse the timestamp without Weekday part. To do parsing including, specify Timestmap format while import or in props.conf.
[yoursourcetype]
TIME_FORMAT = %a %b %d %H:%M:%S %Z %Y
.
.
whats the issue in this, it's pretty straight forward for splunk, reading it properly with the timezone as well.
Splunk does not need the day of the week in text, because it is there in number. Have you tried specifying a TIME_FORMAT without it?
%B %d %H:%M:%S %Z %Y