Splunk Search

How to ingest elapsed time

gmbenz0726
New Member

My file contains data like this:

85119.805: [GC pause (G1 Evacuation Pause) (young) 218M->81M(256M), 0.0159821 secs]
87180.697: [GC pause (G1 Evacuation Pause) (young) 220M->82M(256M), 0.0115120 secs]

Where the number at the beginning of each line is the elapsed seconds since the file was opened.

How do I ingest this into a date/time stamp?

Tags (1)
0 Karma

woodcock
Esteemed Legend

You cannot. The best you can do is use DATETIME=CURRENT in props.conf.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...