Getting Data In

Handy timestamp format extraction tool

rturk
Builder

Hi Splunkers!

This is less of a question, and more of a (hopefully) handy tip that I hope will answer peoples questions when they go looking for an answer to timestamp extraction issues, specifically when setting TIMESTAMP_FORMAT in props.conf.

If you're looking to get a timestamp in strptime/strftime format, I've found this site really useful:

http://www.strftime.net/

It's not owned/run by me, and as far as I can tell has no ads.

Hope it helps!

RT 🙂

0 Karma
1 Solution

rturk
Builder

Like I said, this is just to hopefully help people out - so I'll answer my own question 🙂

View solution in original post

0 Karma

rturk
Builder

Like I said, this is just to hopefully help people out - so I'll answer my own question 🙂

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...