Getting Data In

How to do custom timestamp parsing?

the_sigma
Explorer

I'm looking to use the following as my timestamp.  What should I use in props as my timestamp format and timestamp prefix.
[20230718:001541.421] : [WARN ]

Labels (2)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @the_sigma ,

if the timestamp it's at the beginning of the event, you could try:

TIME_PREFIX = ^\[
TIME_FORMAT = %Y%m%d:%H%M%S.%3N

If it isn't at the end of the event, please share some sample of your events, eventually masked, but with the same structure.

Ciao.

Giuseppe

 

0 Karma

the_sigma
Explorer

I tried your string in the datapreview screen.  I placed it in the timestamp format field.  I used \d{8}\:\d{6}\.\d{3} as the prefix put I'm still getting timestamp=none

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The prefix is the part that comes *before* the timestamp string and must not describe the timestamp string itself.  The prefix for the sample event would be ^[

---
If this reply helps you, Karma would be appreciated.
0 Karma

the_sigma
Explorer

I had already tried that as well but with no luck.  It has to be something else that I missing.  Thanks for replying though.   If I figure it out, I'll post an update here.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Assuming that represents 18 July 23 00:15:41.421 then the format string would be %Y%m%d:%H%M%S.%3N

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...