Getting Data In

Any idea on where I am going wrong with bash_history timestamping?

daniel333
Builder

All,

I am extracting bash_history, the event looks like this.

#1510170881
grep -r something *

But ends up with this timestamp
5/23/18 12:05:39.000 PM

I believe it should be
5/23/18 22:08:30.000 PM

My props.conf looks like this -

[bash_history]
 BREAK_ONLY_BEFORE = #(?=\d+)
 MAX_TIMESTAMP_LOOKAHEAD = 11
 SHOULD_LINEMERGE = true
 TIME_FORMAT = %s
 TIME_PREFIX = #
 TRANSFORMS-bashhistory = route_to_indexers

Any ideas where I might be going wrong with this?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Is the bash_history file in a different time zone from your Splunk account setting?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...