Quantcast
Channel: Questions in topic: "props.conf"
Viewing all articles
Browse latest Browse all 1485

How to edit props.conf to use the "last modified" time of the file as the timestamp for each event?

$
0
0
I have configured monitoring for a set of files. I have configured the props.conf to use the 'last modified' time of the file as the timestamp for each event. However, the events are being indexed for 04/10/2014 for some reason. Sample files on the server with their last modified times: -rw-r--r--. 1 datasvcs datasvcs 14239 Jan 27 11:00 filename20170127_10.gz -rw-r--r--. 1 datasvcs datasvcs 14497 Jan 27 12:00 filename20170127_11.gz -rw-r--r--. 1 datasvcs datasvcs 14143 Jan 27 13:00 filename20170127_12.gz Indexed data for said files (notice the _time from below vs the last modified time from above): source _time count /data/datasvcs/directory_path/filename20170127_10.gz 2014-04-10 465 /data/datasvcs/directory_path/filename20170127_11.gz 2014-04-10 473 /data/datasvcs/directory_path/filename20170127_12.gz 2014-04-10 453 Props.conf configuration: /opt/splunk/etc/slave-apps//local/props.conf [sourcetype_name] /opt/splunk/etc/slave-apps//local/props.conf DATETIME_CONFIG = NONE /opt/splunk/etc/slave-apps//local/props.conf FIELD_NAMES = /opt/splunk/etc/slave-apps//local/props.conf INDEXED_EXTRACTIONS = csv /opt/splunk/etc/slave-apps//local/props.conf KV_MODE = none /opt/splunk/etc/slave-apps//local/props.conf NO_BINARY_CHECK = true /opt/splunk/etc/slave-apps//local/props.conf SHOULD_LINEMERGE = false /opt/splunk/etc/slave-apps//local/props.conf TIMESTAMP_FIELDS = nanos /opt/splunk/etc/slave-apps//local/props.conf TIME_FORMAT = %s%9N /opt/splunk/etc/slave-apps//local/props.conf category = Custom /opt/splunk/etc/slave-apps//local/props.conf description = CSV for Oceans Order Accepted (SeqOrderAcceptedMessage) /opt/splunk/etc/slave-apps//local/props.conf disabled = false /opt/splunk/etc/slave-apps//local/props.conf pulldown_type = true /opt/splunk/etc/system/default/props.conf ANNOTATE_PUNCT = True /opt/splunk/etc/system/default/props.conf AUTO_KV_JSON = true /opt/splunk/etc/system/default/props.conf BREAK_ONLY_BEFORE = /opt/splunk/etc/system/default/props.conf BREAK_ONLY_BEFORE_DATE = True /opt/splunk/etc/system/default/props.conf CHARSET = UTF-8 /opt/splunk/etc/system/default/props.conf HEADER_MODE = /opt/splunk/etc/system/default/props.conf LEARN_MODEL = true /opt/splunk/etc/system/default/props.conf LEARN_SOURCETYPE = true /opt/splunk/etc/system/default/props.conf LINE_BREAKER_LOOKBEHIND = 100 /opt/splunk/etc/system/default/props.conf MAX_DAYS_AGO = 2000 /opt/splunk/etc/system/default/props.conf MAX_DAYS_HENCE = 2 /opt/splunk/etc/system/default/props.conf MAX_DIFF_SECS_AGO = 3600 /opt/splunk/etc/system/default/props.conf MAX_DIFF_SECS_HENCE = 604800 /opt/splunk/etc/system/default/props.conf MAX_EVENTS = 256 /opt/splunk/etc/system/default/props.conf MAX_TIMESTAMP_LOOKAHEAD = 128 /opt/splunk/etc/system/default/props.conf MUST_BREAK_AFTER = /opt/splunk/etc/system/default/props.conf MUST_NOT_BREAK_AFTER = /opt/splunk/etc/system/default/props.conf MUST_NOT_BREAK_BEFORE = /opt/splunk/etc/system/default/props.conf SEGMENTATION = indexing /opt/splunk/etc/system/default/props.conf SEGMENTATION-all = full /opt/splunk/etc/system/default/props.conf SEGMENTATION-inner = inner /opt/splunk/etc/system/default/props.conf SEGMENTATION-outer = outer /opt/splunk/etc/system/default/props.conf SEGMENTATION-raw = none /opt/splunk/etc/system/default/props.conf SEGMENTATION-standard = standard /opt/splunk/etc/system/default/props.conf TRANSFORMS = /opt/splunk/etc/system/default/props.conf TRUNCATE = 10000 /opt/splunk/etc/system/default/props.conf detect_trailing_nulls = false /opt/splunk/etc/system/default/props.conf maxDist = 100 /opt/splunk/etc/system/default/props.conf priority = /opt/splunk/etc/system/default/props.conf sourcetype = Any assistance would be appreciated.

Viewing all articles
Browse latest Browse all 1485

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>