Getting Data In

Help me write my props.con for this log?

daniel333
Builder

All,

I have a log that looks like this? UTC time. What would my props.conf for this look like for that EPOCH timestamp?

system server.domain.com 192.168.1.11 start 1567632918.94
system server.domain.com 192.168.1.11 stop 1567632918.94

Tags (1)
0 Karma
1 Solution

rupesh26
Path Finder

can you try this

[your_sourcetype]
TIME_PREFIX=\d+.\d+.\d+.\d+\s\w+\s
TIME_FORMAT=%s.%2N

View solution in original post

0 Karma

rupesh26
Path Finder

can you try this

[your_sourcetype]
TIME_PREFIX=\d+.\d+.\d+.\d+\s\w+\s
TIME_FORMAT=%s.%2N

0 Karma
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...