Getting Data In

Handy timestamp format extraction tool

rturk
Builder

Hi Splunkers!

This is less of a question, and more of a (hopefully) handy tip that I hope will answer peoples questions when they go looking for an answer to timestamp extraction issues, specifically when setting TIMESTAMP_FORMAT in props.conf.

If you're looking to get a timestamp in strptime/strftime format, I've found this site really useful:

http://www.strftime.net/

It's not owned/run by me, and as far as I can tell has no ads.

Hope it helps!

RT 🙂

0 Karma
1 Solution

rturk
Builder

Like I said, this is just to hopefully help people out - so I'll answer my own question 🙂

View solution in original post

0 Karma

rturk
Builder

Like I said, this is just to hopefully help people out - so I'll answer my own question 🙂

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...