Getting Data In

Do I need to escape a pipe character for TIME_FORMAT in props.conf?

bwooden
Splunk Employee
Splunk Employee

Do I need to escape the | (pipe character) for a TIME_FORMAT in props.conf?

Example Timestamp:

2014-02-07 || 5:30:02
Tags (3)
0 Karma
1 Solution

bwooden
Splunk Employee
Splunk Employee

No you do not. Your TIME_FORMAT would look like this:

TIME_FORMAT=%Y-%m-%d || %H:%M:%S

Per:

http://docs.splunk.com/Documentation/Splunk/latest/admin/Propsconf
http://docs.splunk.com/Documentation/Splunk/latest/Data/Configuretimestamprecognition

NB: You would escape a pipe in a TIME_PREFIX

View solution in original post

0 Karma

bwooden
Splunk Employee
Splunk Employee

No you do not. Your TIME_FORMAT would look like this:

TIME_FORMAT=%Y-%m-%d || %H:%M:%S

Per:

http://docs.splunk.com/Documentation/Splunk/latest/admin/Propsconf
http://docs.splunk.com/Documentation/Splunk/latest/Data/Configuretimestamprecognition

NB: You would escape a pipe in a TIME_PREFIX

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...