In my Splunkd log for one of our webspheres I'm finding multiple entries with;
DateParserVerbose - Failed to parse timestamp. Defaulting to timestamp of previous event ...
Please can anyone advise what might be the fix for this?
Do I need to create my own sourcetype? with props.conf?
Just insert this line inside your props sourcetype section:
DATETIME_CONFIG = CURRENT
your timestamp extraction not working properly, make changes in props.conf http://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf
-Kamal Bisht
geez, how I love RTFM answers...
When I use data preview - should I see the issue? Are the green values highlighted the problem or a good match on timestamp?