Getting Data In

Having difficulties with a date/time conversion?

NanSplk01
Communicator

I have been trying to create this sourcetype and am not sure I'm capturing it correctly.  

 

Sample date:      [2023-03-26T14:06:06.356-04:00]

Regex Breakdown:    \[\d{4}-\d{2}-\d{2}.\d{2}:\d{2}:\d{2}.\d{3}-\d{2}:\d{2}]

Timestamp:    %Y-%m-%d{2}\T\d{2}:%H%:%M.%S.%N-\d{2}:\d{2}

But I'm having issues with the timestamp value.  I've not run into one that has no breaks in it before.  Any help will be much appreciated.

Labels (2)
0 Karma

yeahnah
Motivator

Hi @NanSplk01 

 The regex looks OK, but time format variables used are wrong.  Here's the Splunk doc ref

https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Commontimeformatvariables

This should work for you

Timestamp: %Y-%m-%dT%H:%M:%S.%3N%z

Hope that helps 

Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...