Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to troubleshoot why the wrong timestamps are being parsed for a dhcpd.leases file?

$
0
0
I'm trying to read in a dhcpd.leases file, but some of my entries are getting the wrong timestamp, and I'm not sure how to debug it. When I first load the file, the parser recognizes the correct time stamp: ![alt text][1] But then, when reviewing the events, a lot of them (~25%) have the wrong timestamp ![alt text][2] Note the _time is 9/17/16 instead of 6/24/14 Is this just a problem with auto extraction of the timestamp? Is there a way to debug the extraction with these events ? [1]: /storage/temp/141184-screen-shot-2016-06-17-at-124355-pm.jpeg [2]: /storage/temp/141186-screen-shot-2016-06-17-at-124811-pm.jpeg

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>