All Apps and Add-ons

Trying to apply timestamp from an epoch format column in db connect

New Member

Hello guys,
I am new here in splunk and in my first project I have to index logs from a remote server and I am doing this with db connect.

My problem is that when I index all the data from this server, the Time that is login into splunk is the Time when Splunk pull the data and I need to log these event by the time that they are generated.

I figured out that when you pull data by the first time with db connect, you can indicate the timestamp by a column of the data base, luckily these db have a time column called "clock", but unforntunlly this time format is in epoch, like so: alt text

So my question is, what do I have to write over here?: alt text

I tryed with %s without any results. Thank you c:

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!