Getting Data In

Correct timestamp format for this dbx column

virtualpony
Path Finder

I have a datetime SQL column that I am indexing with the DBX app. I am trying to figure out the correct timestamp format to use for an output like: 1355960605.253

Thanks

Tags (2)
0 Karma

lguinn2
Legend

This looks like epoch time to me. If it is, then Splunk will figure it out properly. You could also put this in props.conf

[yoursourcetypehere]
TIME_FORMAT=%s%3N

If you want to give Splunk a little more help, you might add a TIME_PREFIX setting and MAX_TIMESTAMP_LOOKAHEAD = 20

Refer to Configure timestamp recognition in the manuals for more info.

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.