Alerting

Time format

uagraw01
Motivator

Please help me to get the time format for the below string in props.conf. I am confused with the last three patterns (533+00:00)

 

2023-12-05T04:21:21,533+00:00

 

Thanks in advance.

0 Karma
1 Solution

azteksites
Explorer

You can try the following TIME_FORMAT value to parse the timestamp,

TIME_FORMAT = %Y-%m-%dT%H:%M:%S,%3N%z

 

View solution in original post

0 Karma

azteksites
Explorer

You can try the following TIME_FORMAT value to parse the timestamp,

TIME_FORMAT = %Y-%m-%dT%H:%M:%S,%3N%z

 

0 Karma

uagraw01
Motivator

@azteksites 

I am still confused for 00:00 (for last two pattern )

uagraw01_0-1701753929561.png

 

0 Karma

azteksites
Explorer

@uagraw01 

00:00 is an offset from UTC. The %z value should parse this in -/+HHMM format.

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @uagraw01 

it seems ,533 is milliseconds

2023-12-05T04:21:21,533+00:00

%Y-%m-%dT%H:%S,%3Q+00:00

0 Karma

uagraw01
Motivator

Thanks for the answer .

By the way have you missed %M ?

 

should be like this: %Y-%m-%dT%H:%M:%S,%3Q+00:00

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Data Management Digest – June 2026

Welcome to the June 2026 edition of Data Management Digest! This month’s update is short and sweet, with a ...

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...