Getting Data In

How can I take the second timestamp in props.conf?

lorscardala985
Explorer

how can i in the props.conf file tell Splunk to take the second timestamp as opposed to the first

Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

In this case you could try something like 

 

^(\w+[\s:\.]+){9}

 

on your TIME_PREFIX.  I assume that 1st timestamp field is first characters on your log entry. If not then ^ should be fixed to match where this starts.

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

this depends on your log file's content. Can you share it?

In common level you could add TIME_PREFIX on your props.conf to recognise correct place where your timestamp starts. See more from here https://docs.splunk.com/Documentation/Splunk/9.1.0/Data/Configuretimestamprecognition

r. Ismo

0 Karma

lorscardala985
Explorer

i have events with this timestamp Sep 20 11:13:18 10.50.3.100 Sep 20 11:13:15 and i want to view only the second timestamp 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

In this case you could try something like 

 

^(\w+[\s:\.]+){9}

 

on your TIME_PREFIX.  I assume that 1st timestamp field is first characters on your log entry. If not then ^ should be fixed to match where this starts.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...