<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding Multiple time stamp fields in props file sourcetype stanza in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Adding-Multiple-time-stamp-fields-in-props-file-sourcetype/m-p/211405#M96218</link>
    <description>&lt;P&gt;can you add some sample events?&lt;/P&gt;</description>
    <pubDate>Mon, 07 Nov 2016 13:18:20 GMT</pubDate>
    <dc:creator>niketn</dc:creator>
    <dc:date>2016-11-07T13:18:20Z</dc:date>
    <item>
      <title>Adding Multiple time stamp fields in props file sourcetype stanza</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-Multiple-time-stamp-fields-in-props-file-sourcetype/m-p/211404#M96217</link>
      <description>&lt;P&gt;I have a source file with multiple dates and timestamp as separate fields. I want to use last_changed and last_changed_time fields..&lt;BR /&gt;
Both are in different format&lt;BR /&gt;
last_changed = %d.%m.%Y&lt;BR /&gt;
last_changed_time = %H:%M:%S %p&lt;/P&gt;

&lt;P&gt;While defining sourcetype - Timestamp fields - last_changed,last_changed_time ... How to give timestamp format since 2 fields are present in timestamp fields? Please suggest!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:41:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-Multiple-time-stamp-fields-in-props-file-sourcetype/m-p/211404#M96217</guid>
      <dc:creator>k_harini</dc:creator>
      <dc:date>2020-09-29T11:41:18Z</dc:date>
    </item>
    <item>
      <title>Re: Adding Multiple time stamp fields in props file sourcetype stanza</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-Multiple-time-stamp-fields-in-props-file-sourcetype/m-p/211405#M96218</link>
      <description>&lt;P&gt;can you add some sample events?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 13:18:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-Multiple-time-stamp-fields-in-props-file-sourcetype/m-p/211405#M96218</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2016-11-07T13:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Adding Multiple time stamp fields in props file sourcetype stanza</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-Multiple-time-stamp-fields-in-props-file-sourcetype/m-p/211406#M96219</link>
      <description>&lt;P&gt;Hi k_harini,&lt;BR /&gt;
if you could share an example will be more efficient.&lt;BR /&gt;
Every way, if you have something like this:&lt;BR /&gt;
01.11.2016|01.11.2016|02.11.2016|11:58:56 AM|11:58:57 AM|11:59:09 AM&lt;BR /&gt;
and you need to take the first and the fourth fields, you could use in TIMESTAMP_FORMAT something like this &lt;CODE&gt;%d.%m.%Y\|\d+\.\d+\.\d+\|\d+\.\d+\.\d+\|%H:%M:%S %p&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:46:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-Multiple-time-stamp-fields-in-props-file-sourcetype/m-p/211406#M96219</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-29T11:46:18Z</dc:date>
    </item>
  </channel>
</rss>

