Getting Data In

Having difficulties with a date/time conversion?

NanSplk01
Communicator

I have been trying to create this sourcetype and am not sure I'm capturing it correctly.  

 

Sample date:      [2023-03-26T14:06:06.356-04:00]

Regex Breakdown:    \[\d{4}-\d{2}-\d{2}.\d{2}:\d{2}:\d{2}.\d{3}-\d{2}:\d{2}]

Timestamp:    %Y-%m-%d{2}\T\d{2}:%H%:%M.%S.%N-\d{2}:\d{2}

But I'm having issues with the timestamp value.  I've not run into one that has no breaks in it before.  Any help will be much appreciated.

Labels (2)
0 Karma

yeahnah
Motivator

Hi @NanSplk01 

 The regex looks OK, but time format variables used are wrong.  Here's the Splunk doc ref

https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Commontimeformatvariables

This should work for you

Timestamp: %Y-%m-%dT%H:%M:%S.%3N%z

Hope that helps 

Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...