Getting Data In

Handling events with the same timestamp

New Member

I am extracting logs from a file which contain entries with two timestamp log entries:
1. eventTimestamp
2. timestamp

The later is included by my logging framework. I occasionally write events where the timestamp is the same. In these cases the events gets grouped together as shown below:

The events below would all appear under the timestamp: 2016-12-28T17:07:55.946Z.


I have tried creating a props.conf file with the following configuration:


However, I am continuing to experience the issue. I have followed [1] to determine if my props.conf file is read and it seems to be the case. The configuration given above were taken from [2].


Revered Legend

Try this for your props.conf (on Indexer or Heavy Forwarder)

LINE_BREAKER = ([\r\n]+)(?=\{\"eventCode\")
TIME_PREFIX = eventTimestamp\":\"
TIME_FORMAT = %Y-%m-%dT%H:%M:%S.%3N
New Member

Thank You.

I did not get a chance to try it out yet. I will update the thread once I get a chance to test it.

