 
					
				
		
I have a log file where i need to do a Timestamp extraction which is in the middle of the log....
somehow it's capturing   2017 8:09:16 PM  Is R(from the next line)
NewStatServer ----------------------------------
Started Time: 3/16/2017 8:09:16 PM
Is Running: True
TIME_FORMAT = %m/%d/%Y  %H:%M:%S %p
TIME_PREFIX = Started\sTime\:\s
MAX_TIMESTAMP_LOOKAHEAD = 20
 
					
				
		
Try this (every line has changed):
TIME_FORMAT = %m/%d/%Y  %I:%M:%S %p
TIME_PREFIX = [\r\n]Started Time:\s*
MAX_TIMESTAMP_LOOKAHEAD = 22
Deploy to your Indexers and restart your Splunk instances there. Test by checking ONLY for events indexed AFTER the restarts.
 
					
				
		
Try this (every line has changed):
TIME_FORMAT = %m/%d/%Y  %I:%M:%S %p
TIME_PREFIX = [\r\n]Started Time:\s*
MAX_TIMESTAMP_LOOKAHEAD = 22
Deploy to your Indexers and restart your Splunk instances there. Test by checking ONLY for events indexed AFTER the restarts.
