Getting Data In

how to get splunk to read the correct date and time from events?

remy06
Contributor

Hi,

How do I get splunk to show the date and time correctly based on the event?For example if I have the following event from oracle logs:

RETURNCODE=0,OS_PROCESS=1671350,EXTENDED_TIMESTAMP="22/07/10 12:55:50.251291 PM +08:00",TO_CHAR(EXTENDED_TIMESTAMP,'MM="07/22/2010 12:55:50",OS_USERNAME=,USERNAME=,USERHOST=,OBJ_NAME=,SCN=,ACTION=,TRANSACTIONID=,ACTION_NAME=""

Splunk is displaying the incorrect date as:
10/12/07 <-- translate to year 2007..
12:55:50.565 PM

Some events may translate with incorrect time as well.

Have tried using "DATETIME config=current" in props.conf,but still there is a time differences as the splunk and oracle server time is not in sync.

Any idea?

1 Solution

Genti
Splunk Employee
Splunk Employee

remy you can try something like this:

[source::e:\logs\yourlogs\*]
MAX_TIMESTAMP_LOOKAHEAD = 75
TIME_FORMAT = %d/%m/%y %H:%M:%S

Here are the docs on this, read them for more knowledge on how to deal with this: Configure Timestamp Recognition

Cheers,
.gz

View solution in original post

0 Karma

Genti
Splunk Employee
Splunk Employee

remy you can try something like this:

[source::e:\logs\yourlogs\*]
MAX_TIMESTAMP_LOOKAHEAD = 75
TIME_FORMAT = %d/%m/%y %H:%M:%S

Here are the docs on this, read them for more knowledge on how to deal with this: Configure Timestamp Recognition

Cheers,
.gz

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...