Splunk Search

Train dates fails to recognize any date format

mrdaniel
Explorer

I have tried to get Splunk to recognize a new format of dates but im unable even to get the train date to understand the date, i only get : "Skipping unpromissing line" when running that on the logfile. The date and time is in the following format:

11032011 101305
11032011 101304

MMDDYYYY HHMMSS

I would need help to proceed to get Splunk to be able to recognize this date format.

Tags (1)
0 Karma

tgow
Splunk Employee
Splunk Employee

You will need to modify the props.conf with the following (assuming 24-hour clock) :

[yoursourcetype]
TIME_FORMAT = %m%d%Y %H%M%S

Here is a link to more information:

http://docs.splunk.com/Documentation/Splunk/4.2.3/Data/Configuretimestamprecognition

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...