Getting Data In

Correct timestamp format for this dbx column

Path Finder

I have a datetime SQL column that I am indexing with the DBX app. I am trying to figure out the correct timestamp format to use for an output like: 1355960605.253


Tags (2)
0 Karma


This looks like epoch time to me. If it is, then Splunk will figure it out properly. You could also put this in props.conf


If you want to give Splunk a little more help, you might add a TIME_PREFIX setting and MAX_TIMESTAMP_LOOKAHEAD = 20

Refer to Configure timestamp recognition in the manuals for more info.

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!