All Apps and Add-ons

Splunk 5.x App for Microsoft Windows: How to change the default timestamp in App to the timestamp in present data?

angshul
Path Finder

I'm building a Splunk App and would like to create some timecharts and other visualizations.
However, I would like to use the timestamp present in the data I'm sending to the app instead of the system time.
My data has timestamps as given below:
1/1/2000 12:00:00 AM
1/1/2016 12:00:00 AM
4/29/2019 5:32:00 PM
3/16/2018 9:41:00 PM

I want to modify the default Splunk timestamp to the entries from my data.

0 Karma

kgderrekchapin
Path Finder

You will likely need to configure your TIME_FORMAT in props.conf. However, without seeing the data it's hard to say. You should take a read through https://docs.splunk.com/Documentation/Splunk/7.3.0/Data/Configuretimestamprecognition this should help you in isolating down timestamp in your data.

0 Karma
Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...