How to Extract the timestamp (Date: in below screenshot) which is in UTC format and convert to CST format? current timestamp is indexing timestamp.
[ _json ]
BREAK_ONLY_BEFORE={"preview"
pulldown_type=true
TIME_PREFIX=\s\\"date\\":\s+\\"
Try this or above stanza
[ _json ]
BREAK_ONLY_BEFORE={"preview"
TIME_PREFIX=\s\\"date\\":\s+\\"
TIME_FORMAT=%Y-%m-%dT%H:%M:%S+%N:%N
TRUNCATE=9999999
TIME_PREFIX = timestamp:\s+
TIME_FORMAT = %s
in props.conf
I tried it din't work.
yoursearch| eval CST_time=_time-21600| convert ctime(CST_time)|table CST_time , _time
yoursearch| eval CST_time=now()-21600| convert ctime(CST_time)|table CST_time , _time
Central Standard Time (CST) is 6 hours behind Coordinated Universal Time (UTC).
where your _time is UTC
Is there a way to do it at indexing time?