Getting Data In

How to do custom timestamp parsing?

the_sigma
Explorer

I'm looking to use the following as my timestamp.  What should I use in props as my timestamp format and timestamp prefix.
[20230718:001541.421] : [WARN ]

Labels (2)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @the_sigma ,

if the timestamp it's at the beginning of the event, you could try:

TIME_PREFIX = ^\[
TIME_FORMAT = %Y%m%d:%H%M%S.%3N

If it isn't at the end of the event, please share some sample of your events, eventually masked, but with the same structure.

Ciao.

Giuseppe

 

0 Karma

the_sigma
Explorer

I tried your string in the datapreview screen.  I placed it in the timestamp format field.  I used \d{8}\:\d{6}\.\d{3} as the prefix put I'm still getting timestamp=none

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The prefix is the part that comes *before* the timestamp string and must not describe the timestamp string itself.  The prefix for the sample event would be ^[

---
If this reply helps you, Karma would be appreciated.
0 Karma

the_sigma
Explorer

I had already tried that as well but with no luck.  It has to be something else that I missing.  Thanks for replying though.   If I figure it out, I'll post an update here.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Assuming that represents 18 July 23 00:15:41.421 then the format string would be %Y%m%d:%H%M%S.%3N

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...