Deployment Architecture

Help with Time prefix and date format

nipendo
Engager

What time prefix and time format should I use.
I will appreciate your help with this one.

=INFO REPORT==== 15-Jan-2018::09:51:48 ===
connection <0.9091.502> (192.168.1.56:61982 -> 192.168.1.81:5672): user aaaa' authenticated and granted access to vhost '/'

=INFO REPORT==== 15-Jan-2018::09:51:48 ===
closing AMQP connection <0.9091.502> (192.168.1.56:61982 -> 192.168.1.81:5672, vhost: '/', user: 'aan')

=WARNING REPORT==== 15-Jan-2018::09:51:48 ===
Could not find handle.exe, please install from sysinternals

Tags (2)
0 Karma
1 Solution

mayurr98
Super Champion

hey try this

TIME_FORMAT = %d-%b-%Y::%H:%M:%S
TIME_PREFIX = REPORT====\s

let me know if this helps !

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Try these settings.

TIME_PREFIX = =
TIME_FORMAT = %d-%b-%Y::%H:%M:%S
---
If this reply helps you, Karma would be appreciated.
0 Karma

mayurr98
Super Champion

hey try this

TIME_FORMAT = %d-%b-%Y::%H:%M:%S
TIME_PREFIX = REPORT====\s

let me know if this helps !

cmerriman
Super Champion

are you trying to extract a timestamp from these logs during index or during search?

0 Karma

nipendo
Engager

i am trying to index these logs.
i want to know what should i write in props.conf
like:
MAX_TIMESTAMP_LOOKAHEAD = 50
NO_BINARY_CHECK = true
TIME_FORMAT = %d/%m/%Y %H:%M:%S.%3N
TIME_PREFIX = ^
category = Custom

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...