Getting Data In

Time stamp on custom imported file @Please Help@

j666gak
Communicator

Hello,

I have never done an import on Splunk, so i'm sorry if this has been asked although I can't find it if it has.

I am trying to import a web usage log that is in the following format(below). I have tried doing a custom import as it didn't fit any of the preset ones, although when looking in Splunk after indexing the time stamp is completely wrong.

Tue 03 Jan 2012 10:25:57 AM CET

Considerations -
* Don't need the day "Tue"
* Month is not a numerical value ie 01 for Jan
* Not in 24hr format so shows AM/PM
* Time on the log was taken in CET, is it possible to convert to GMT London? same as Splunk server

I really need help on how to configure this please. If anybody can help I would be really greatful, thanks for your time.

Cheers
Guy

0 Karma

lguinn2
Legend

BTW, you can tell Splunk that the input is in one of the following known web log formats:
access_combined (Apache)
access_combined_wcookie (Apache)
iis (Microsoft IIS)

You can find this by choosing More Options, and then setting the value for sourcetype (you will need to select Manual instead of Automatic) to do this.

0 Karma

MarioM
Motivator
0 Karma

lguinn2
Legend

Splunk is usually very good at parsing timestamps in exactly this format. So, can you show us a few complete events? (anonymizing any private stuff of course) I suspect that Splunk is just confused about where to find the timestamp within the event, not with the format itself.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...