Getting Data In

Having difficulties with a date/time conversion?

NanSplk01
Communicator

I have been trying to create this sourcetype and am not sure I'm capturing it correctly.  

 

Sample date:      [2023-03-26T14:06:06.356-04:00]

Regex Breakdown:    \[\d{4}-\d{2}-\d{2}.\d{2}:\d{2}:\d{2}.\d{3}-\d{2}:\d{2}]

Timestamp:    %Y-%m-%d{2}\T\d{2}:%H%:%M.%S.%N-\d{2}:\d{2}

But I'm having issues with the timestamp value.  I've not run into one that has no breaks in it before.  Any help will be much appreciated.

Labels (2)
0 Karma

yeahnah
Motivator

Hi @NanSplk01 

 The regex looks OK, but time format variables used are wrong.  Here's the Splunk doc ref

https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Commontimeformatvariables

This should work for you

Timestamp: %Y-%m-%dT%H:%M:%S.%3N%z

Hope that helps 

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...