All Apps and Add-ons

Why is Eventgen not producing data with current timestamps?

abeeber_2
Path Finder

Hi Splunk et al,

I am working on using Eventgen to use access and secure logs.

My test/sample app works as I am seeing events in my data summary, but the timestamps are off. I am seeing the original date/time of the timestamps in my sample log; and not events with current dates and times.

How do I fix that?

Thanks,

Andrew

ps.. below is my code from my eventgen.conf in my sample app

[www1access.log]
index = access
outputMode = modinput
sourcetype = andrew_access
source = www1access.log
interval = 300
earliest=now
latest=now
maxIntervalsBeforeFlush = 1
host = www5
0 Karma

nagendra008
Explorer

Hi Abeeber,

Its best way to keep the field names on the top of the csv. Splunk will pick automatically the as field_name.

file1.csv:
_time,IP,lOC
2016-03-08T23:02:31.000+00:00,10.10.10.1,US
2016-03-08T23:02:31.000+00:00,10.10.10.2,JAP
2016-03-08T23:02:31.000+00:00,10.10.10.3,IND

settings -> Add Data, Monitor--> files and dir( file.csv)
After adding the data you can see in the props.conf -

[checking]
DATETIME_CONFIG =
INDEXED_EXTRACTIONS = csv
KV_MODE = none
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = false
category = Structured
description = Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled = false
pulldown_type = true

You can directly search with the field names [ _time,IP,lOC ]

Regards,
Nagee.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...