All Apps and Add-ons

Splunk 5.x App for Microsoft Windows: How to change the default timestamp in App to the timestamp in present data?

angshul
Path Finder

I'm building a Splunk App and would like to create some timecharts and other visualizations.
However, I would like to use the timestamp present in the data I'm sending to the app instead of the system time.
My data has timestamps as given below:
1/1/2000 12:00:00 AM
1/1/2016 12:00:00 AM
4/29/2019 5:32:00 PM
3/16/2018 9:41:00 PM

I want to modify the default Splunk timestamp to the entries from my data.

0 Karma

kgderrekchapin
Path Finder

You will likely need to configure your TIME_FORMAT in props.conf. However, without seeing the data it's hard to say. You should take a read through https://docs.splunk.com/Documentation/Splunk/7.3.0/Data/Configuretimestamprecognition this should help you in isolating down timestamp in your data.

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...