Getting Data In

Timestamp Issue in Splunk

shwhooda
New Member

Hi,
I am using Splunk for the first time.
I tried looking for the answer in the blogs however the answers were not able to help me.

I have a problem that when i am running a search in splunk it is not taking correct timestamp for some of my log files.
For Eg: for date 5/06/12 -- 5th June, it is returning data as 6th May and for 07/06/12 -- it is giving the correct data. However, at times it is not giving data in 5th june or 6th may. So, in short it is behaving unconsistently.
This is the timestamp from sample log file:
RTS_WS974 05/06/12 01:47:40.722 [20:23:48.870]

I tried updating the props.conf file with this:
TIME_FORMAT = %d/%m/%y %k:%M:%S
for all occurances of TIME_FORMAT in the conf file however i am still facing the same issue.
Any help would be highly appreciated.
Regards,
Shweta

Tags (1)
0 Karma

Ayn
Legend

Have you restarted Splunk after doing these changes? Are you looking at changes in data that comes in after restart only? The changes will not affect timestamps for events that have already been indexed.

EDIT: No, you cannot change the timestamp values for events that are already in the index. You could look at some workarounds if you're interested: http://splunk-base.splunk.com/answers/49888/can-we-modify-a-wrong-timestamp

0 Karma

Ayn
Legend

Updated my answer to include info about timestamps that are already in the index.

0 Karma

shwhooda
New Member

Thanks for your reply.
Yes i restarted splunk.Is there any way to get the changes in data that was already indexed before the restart?
because i am using trial version and can only upload 500mb in a day and i have a lot of data already uploaded for analysis. So this way i am losing all the efforts i spent in past few days in data upload.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...