Getting Data In

How can I take the second timestamp in props.conf?

lorscardala985
Explorer

how can i in the props.conf file tell Splunk to take the second timestamp as opposed to the first

Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

In this case you could try something like 

 

^(\w+[\s:\.]+){9}

 

on your TIME_PREFIX.  I assume that 1st timestamp field is first characters on your log entry. If not then ^ should be fixed to match where this starts.

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

this depends on your log file's content. Can you share it?

In common level you could add TIME_PREFIX on your props.conf to recognise correct place where your timestamp starts. See more from here https://docs.splunk.com/Documentation/Splunk/9.1.0/Data/Configuretimestamprecognition

r. Ismo

0 Karma

lorscardala985
Explorer

i have events with this timestamp Sep 20 11:13:18 10.50.3.100 Sep 20 11:13:15 and i want to view only the second timestamp 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

In this case you could try something like 

 

^(\w+[\s:\.]+){9}

 

on your TIME_PREFIX.  I assume that 1st timestamp field is first characters on your log entry. If not then ^ should be fixed to match where this starts.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...