Alerting

Time format

uagraw01
Motivator

Please help me to get the time format for the below string in props.conf. I am confused with the last three patterns (533+00:00)

 

2023-12-05T04:21:21,533+00:00

 

Thanks in advance.

0 Karma
1 Solution

azteksites
Explorer

You can try the following TIME_FORMAT value to parse the timestamp,

TIME_FORMAT = %Y-%m-%dT%H:%M:%S,%3N%z

 

View solution in original post

0 Karma

azteksites
Explorer

You can try the following TIME_FORMAT value to parse the timestamp,

TIME_FORMAT = %Y-%m-%dT%H:%M:%S,%3N%z

 

0 Karma

uagraw01
Motivator

@azteksites 

I am still confused for 00:00 (for last two pattern )

uagraw01_0-1701753929561.png

 

0 Karma

azteksites
Explorer

@uagraw01 

00:00 is an offset from UTC. The %z value should parse this in -/+HHMM format.

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @uagraw01 

it seems ,533 is milliseconds

2023-12-05T04:21:21,533+00:00

%Y-%m-%dT%H:%S,%3Q+00:00

0 Karma

uagraw01
Motivator

Thanks for the answer .

By the way have you missed %M ?

 

should be like this: %Y-%m-%dT%H:%M:%S,%3Q+00:00

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...