<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple time logs in one timestamp in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Multiple-time-logs-in-one-timestamp/m-p/423029#M173443</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;If you want to extract timestamp from your logs (which has different formats) then you can create custom datetime.xml which will extract correct timestamp, please refer &lt;A href="https://answers.splunk.com/answers/692340/how-can-we-set-time-format-in-propsconf-where-the.html"&gt;https://answers.splunk.com/answers/692340/how-can-we-set-time-format-in-propsconf-where-the.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Jan 2019 12:22:31 GMT</pubDate>
    <dc:creator>harsmarvania57</dc:creator>
    <dc:date>2019-01-24T12:22:31Z</dc:date>
    <item>
      <title>Multiple time logs in one timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multiple-time-logs-in-one-timestamp/m-p/423028#M173442</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;Multiple time logs in one timestamp&lt;BR /&gt;
example&lt;/P&gt;

&lt;P&gt;19/01/24 10:28:51 [2019-01-24 10:28:51] DEBUG [SyslogReceiver.java:212] ## Syslog Process.&lt;BR /&gt;
                                 [2019-01-24 10:28:51] DEBUG [SyslogReceiver.java:179] #### Syslog Message received&lt;BR /&gt;
                                 [2019-01-24 10:28:51] DEBUG [SyslogReceiver.java:220] ## Syslog L3IP Process&lt;/P&gt;

&lt;P&gt;i need field&lt;/P&gt;

&lt;P&gt;19/01/24 10:28:51[2019-01-24 10:28:51] DEBUG [SyslogReceiver.java:212] ## Syslog Process.&lt;BR /&gt;
19/01/24 10:28:51[2019-01-24 10:28:51] DEBUG [SyslogReceiver.java:179] #### Syslog Message received&lt;BR /&gt;
19/01/24 10:28:51[2019-01-24 10:28:51] DEBUG [SyslogReceiver.java:220] ## Syslog L3IP Process&lt;/P&gt;

&lt;P&gt;where is alter&lt;BR /&gt;
$SPLUNK_HOME/etc/system/local/props.conf &lt;/P&gt;

&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 05:06:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multiple-time-logs-in-one-timestamp/m-p/423028#M173442</guid>
      <dc:creator>jsryu0247</dc:creator>
      <dc:date>2019-01-24T05:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple time logs in one timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multiple-time-logs-in-one-timestamp/m-p/423029#M173443</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;If you want to extract timestamp from your logs (which has different formats) then you can create custom datetime.xml which will extract correct timestamp, please refer &lt;A href="https://answers.splunk.com/answers/692340/how-can-we-set-time-format-in-propsconf-where-the.html"&gt;https://answers.splunk.com/answers/692340/how-can-we-set-time-format-in-propsconf-where-the.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 12:22:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multiple-time-logs-in-one-timestamp/m-p/423029#M173443</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-01-24T12:22:31Z</dc:date>
    </item>
  </channel>
</rss>

