Hi
I have two time stamps in my logs. .
say and TIMESTAMP=2012-07-11T06:59:00.008+01:00 ..
How can i say splunk to take one of time as _time . i need the TIMESTAMP to be taken as my loggig event time..so that i can calucate the difference between the events with the help of transacition command...
Please help..
You need to set the TIME_PREFIX
in props.conf.
[yoursourcetype]
TIME_PREFIX = TIMESTAMP=
http://docs.splunk.com/Documentation/Splunk/latest/admin/Propsconf
You need to set the TIME_PREFIX
in props.conf.
[yoursourcetype]
TIME_PREFIX = TIMESTAMP=
http://docs.splunk.com/Documentation/Splunk/latest/admin/Propsconf