Splunk Search

Train dates fails to recognize any date format

mrdaniel
Explorer

I have tried to get Splunk to recognize a new format of dates but im unable even to get the train date to understand the date, i only get : "Skipping unpromissing line" when running that on the logfile. The date and time is in the following format:

11032011 101305
11032011 101304

MMDDYYYY HHMMSS

I would need help to proceed to get Splunk to be able to recognize this date format.

Tags (1)
0 Karma

tgow
Splunk Employee
Splunk Employee

You will need to modify the props.conf with the following (assuming 24-hour clock) :

[yoursourcetype]
TIME_FORMAT = %m%d%Y %H%M%S

Here is a link to more information:

http://docs.splunk.com/Documentation/Splunk/4.2.3/Data/Configuretimestamprecognition

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...