Getting Data In

Splunk timestamp Milliseconds vs Microseconds

jadengoho
Builder

Hi All,
What would be the impact if i use "%Q" rather than "%6Q" ?
Cause i'm seeing a 20min time delay on Splunk ingestion, is this because of this or not ?

Log Example:
- 2020-03-08-15.31.10.838384
- 2020-02-01-18.25.15.738385

https://docs.splunk.com/Documentation/Splunk/8.0.2/SearchReference/Commontimeformatvariables
https://docs.splunk.com/Documentation/Splunk/8.0.2/Troubleshooting/Troubleshootingeventsindexingdela...

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Using the wrong time variable may prevent Splunk from matching your data. At best, it will only accept 3 decimal places.
Since %Q is the same as %3Q, which does not match microseconds, you should use %6Q.

I doubt this explains the 20-minute delay, however. Have you verified the clocks are correct on all systems?

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Using the wrong time variable may prevent Splunk from matching your data. At best, it will only accept 3 decimal places.
Since %Q is the same as %3Q, which does not match microseconds, you should use %6Q.

I doubt this explains the 20-minute delay, however. Have you verified the clocks are correct on all systems?

---
If this reply helps you, Karma would be appreciated.
0 Karma

jadengoho
Builder

Yes the clocks are correct, maybe it's due to other stuff on their server.
Thanks.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...