Getting Data In

How to configure our expected timestamp format in props.conf?

splunker9999
Path Finder

Hi,

We need to format our time stamps using props.conf, since our events do not have date/month/year to our logs, it has only %H:%M:%S. we need to append %Y/%M/%D to every event.

This is for our logs format looks like.

14:55:55,229 INFO [stdout] (ServerService THread Pool--64)ss_debug(1:)Sending secure hello message
14:55:55,232 INFO [stdout] (ServerService THread Pool--64)ss_debug(1:) server created new session

Can you please provide props configuration for this?

Thanks

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

What happens if you just set:

TIME_PREFIX = ^
TIME_FORMAT = %H:%M:%S,%3N
MAX_TIMESTAMP_LOOKAHEAD = 12

Won't it just use the current year anyway?

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...