How does Splunk assign a Timestamp?
In the previous discussions, we have mentioned Splunk assigns timestamps automatically. But how is it happening exactly?
Splunk uses a set of rules in a specific order, which can be called as precedence rules
The first choice, Splunk looks for the explicit time format configured for a particular file In props.conf.
If no explicit TIME_FORMAT is configured, the second choice would be the TIME_FORMAT configured for the source type.
In this example, in the props.conf file, the time format is configured under the source type [android_logs].
So Splunk uses this time format configuration to extract and assign the timestamp.
The third choice is, if the event has only a date and time, but no year, then Splunk determines the year automatically and assigns a timestamp for that event.
In this example, we can see in the event, the 17th of March, and time is present. No year is mentioned. But in the time field, we can see Splunk assigned the year 2023.
The Process of determining the year will be discussed in upcoming slides
If the events do not have any timestamp, then as a fourth choice, Splunk s/w tries to find the date in the source name or the file name. In general, All events must have time even if they don't have a date.
In this example, the source is a log file. As we can see, the date and time are mentioned in the filename. Splunk extracts this as the timestamp.
Fifth choice, For file sources, if no date is mentioned in the file name, Splunk takes the file modification time as the timestamp.
In this example, No date is mentioned in the file name. So Splunk takes the “Date modified” value of that source file as the timestamp.
The sixth choice, Splunk has a file named datetime.xml which has configuration for all the advanced timestamp recognition. It tries to identify timestamps based on those configurations.
As the last option, Splunk software assigns the timestamp from the current system time while indexing data.
As shown in the screenshot - Splunk is not able to extract the date from the event, because the format is not standard, so it is taking the current system date. and time is extracted from the event data.
🆓🆓Free Masterclasses: (With live session 👨💻 at the end)🆓🆓
Splunk Timestamp Extraction Masterclass 101:
https://splunk.softmania.in/course/sp...
Scenario-based Splunk Admin Use Cases - Part 1:
https://splunk.softmania.in/course/sc...
Splunk Search Commands Masterclass 101:
https://splunk.softmania.in/course/sp...
👑👑Soft Mania Premium Subscription👑👑
One-time Subscription with Lifetime access to all masterclasses.
For more details, visit: https://splunk.softmania.in/course/so...
(Subscription charges will spike by 40% on 01-Mar-2024. 📈)
#splunk #splunkadmin #splunkblogs #splunkengineer #splunklife #softmania #splunkmania"
--------------------------------------------------------------------------------------------------------------------
Want to become expert in Splunk SIEM ???
Here is the 4 stage roadmap (With Live Projects) to gain real-time experience
Stage-1: Learn IT basics & Security Essentials
To Learn those topics, Watch below videos for free
1) • Day-1 | Batch-1 | CyberSecurity - Introduc...
2) https://www.youtube.com/live/hVCKZKwB...
3) https://www.youtube.com/live/sUU3wDGj...
4) https://www.youtube.com/live/knrtIdqK...
Stage-2: Learn Splunk basics
To Learn those topics, Register for this beginner bootcamp for free
Link: https://splunk.softmania.in/course/fr...
Stage-3: Do 10+ Live Splunk Projects
To do these projects, enroll for this Intermediate bootcamp
Link: https://splunk.softmania.in/session/s...
Stage-4: Learn Splunk Architect topics
To do these projects, enroll for this Expert bootcamp
Link: https://splunk.softmania.in/course/so...
Need help in deciding?? - DM us on WhatsApp - http://wa.me/918317349618