I have a MySQL table with column 'dateTimeOrigination' where each event records its time of occurrence in Linux time (epoch) like this:
1470925285 (standard 10 symbols). In Splunk DB Connect 2, I configure Output Timestamp Format=Epoch Time, Rising Column='dateTimeOrigination'. Metadata sourcetype is JSON.
What I have in output (indexed) is
1470925 (7 symbols), so Splunk converts it to 1/18/1970 and neither Output format works nor Java date can be established.
How this could happen (suddenly milliseconds are expected?) and how can I fix it?
Hi, using 2.3.0 improves the UI of this area, so it's worth going there... here's the docs section for doing inputs: