Alerting

Time format

uagraw01
Motivator

Please help me to get the time format for the below string in props.conf. I am confused with the last three patterns (533+00:00)

 

2023-12-05T04:21:21,533+00:00

 

Thanks in advance.

0 Karma
1 Solution

azteksites
Explorer

You can try the following TIME_FORMAT value to parse the timestamp,

TIME_FORMAT = %Y-%m-%dT%H:%M:%S,%3N%z

 

View solution in original post

0 Karma

azteksites
Explorer

You can try the following TIME_FORMAT value to parse the timestamp,

TIME_FORMAT = %Y-%m-%dT%H:%M:%S,%3N%z

 

0 Karma

uagraw01
Motivator

@azteksites 

I am still confused for 00:00 (for last two pattern )

uagraw01_0-1701753929561.png

 

0 Karma

azteksites
Explorer

@uagraw01 

00:00 is an offset from UTC. The %z value should parse this in -/+HHMM format.

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @uagraw01 

it seems ,533 is milliseconds

2023-12-05T04:21:21,533+00:00

%Y-%m-%dT%H:%S,%3Q+00:00

0 Karma

uagraw01
Motivator

Thanks for the answer .

By the way have you missed %M ?

 

should be like this: %Y-%m-%dT%H:%M:%S,%3Q+00:00

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...