Getting Data In

How to edit my props.conf to extract a timestamp in the middle of a log?

prakash007
Builder

I have a log file where i need to do a Timestamp extraction which is in the middle of the log....

somehow it's capturing 2017 8:09:16 PM Is R(from the next line)

NewStatServer ----------------------------------
Started Time: 3/16/2017 8:09:16 PM
Is Running: True

TIME_FORMAT = %m/%d/%Y  %H:%M:%S %p
TIME_PREFIX = Started\sTime\:\s
MAX_TIMESTAMP_LOOKAHEAD = 20
0 Karma
1 Solution

woodcock
Esteemed Legend

Try this (every line has changed):

TIME_FORMAT = %m/%d/%Y  %I:%M:%S %p
TIME_PREFIX = [\r\n]Started Time:\s*
MAX_TIMESTAMP_LOOKAHEAD = 22

Deploy to your Indexers and restart your Splunk instances there. Test by checking ONLY for events indexed AFTER the restarts.

View solution in original post

0 Karma

woodcock
Esteemed Legend

Try this (every line has changed):

TIME_FORMAT = %m/%d/%Y  %I:%M:%S %p
TIME_PREFIX = [\r\n]Started Time:\s*
MAX_TIMESTAMP_LOOKAHEAD = 22

Deploy to your Indexers and restart your Splunk instances there. Test by checking ONLY for events indexed AFTER the restarts.

0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...