Getting Data In

How can I take the second timestamp in props.conf?

lorscardala985
Explorer

how can i in the props.conf file tell Splunk to take the second timestamp as opposed to the first

Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

In this case you could try something like 

 

^(\w+[\s:\.]+){9}

 

on your TIME_PREFIX.  I assume that 1st timestamp field is first characters on your log entry. If not then ^ should be fixed to match where this starts.

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

this depends on your log file's content. Can you share it?

In common level you could add TIME_PREFIX on your props.conf to recognise correct place where your timestamp starts. See more from here https://docs.splunk.com/Documentation/Splunk/9.1.0/Data/Configuretimestamprecognition

r. Ismo

0 Karma

lorscardala985
Explorer

i have events with this timestamp Sep 20 11:13:18 10.50.3.100 Sep 20 11:13:15 and i want to view only the second timestamp 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

In this case you could try something like 

 

^(\w+[\s:\.]+){9}

 

on your TIME_PREFIX.  I assume that 1st timestamp field is first characters on your log entry. If not then ^ should be fixed to match where this starts.

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...