Getting Data In

Edit of Time_format in props.conf on Cluster Master does not strike through

yAlff
Path Finder

Hello Community,

My Setup is 1 SearchHead, 1 Cluster Master, 2 Indexers and a bunch of Forwarders.
A logfile looks something like that:

<134>Aug 14 07:46:04 pm-1234

With pm-1234 as the host name. So Splunk does interpret the pm in the host name as past morning. In the example the interpreted time would be 19:46:04, but it it correctly 07:46:04 AM.

Yesterday, I added to the sourcetype in props.conf on Cluster Master following line:

TIME_FORMAT=%b %d %H:%M:%S

Followed by command

splunk apply cluster-bundle

But as I looked this morning, the new logfile entries are still interpreted false.

What did I forget?

Note: If I ingest the data and define another sourcetype for the data, where I set the TIME_FORMAT right, the timestamp is interpreted correctly; but this is not an option for me; it was only for testing. But if I edit this sourcetype in props.conf, I don't see that the change was successful.

0 Karma
1 Solution

yAlff
Path Finder

Ok, I had to use

TIME_PREFIX=<134>

now it works! Fine 🙂

View solution in original post

0 Karma

yAlff
Path Finder

Ok, I had to use

TIME_PREFIX=<134>

now it works! Fine 🙂

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...