Seeking help with TIME_FORMAT in props.conf.
I'm trying to get Splunk to recognize a time format in the form of "JAN 3 2016". Seems simple enough, but none of the strptime fields address the month field with all caps. For example if it was instead "Jan 3 2016" where only the "J" is capitalized I could use TIME_FORMAT = "%b %e %Y". But because the month is in the format of "JAN" the %b does not recognize the month. Recommendations on how to set TIME_FORMAT?
Would you be able to give the complete date string for timestamp? Also few sample events?
For the following data strptime timestamp format %b %d %Y %H:%M:%S.%3N worked for me:
JAN 3 2016 20:17:13.000, my test data line 1
JAN 3 2016 20:17:14.000, my test data line 2
JAN 3 2016 20:17:15.000, my test data line 3
strptime() is case-insensitive, so there might be something else at fault.
Thank you!
You're welcome, but we can help you get to the bottom of the problem!
Like niketnilay said, if we had a complete date string or a few sample events, we can track down what might really be going on.
Would you be able to give the complete date string for timestamp? Also few sample events?
For the following data strptime timestamp format %b %d %Y %H:%M:%S.%3N worked for me:
JAN 3 2016 20:17:13.000, my test data line 1
JAN 3 2016 20:17:14.000, my test data line 2
JAN 3 2016 20:17:15.000, my test data line 3
@splk5000 I have converted my comment to answer since %d resolved the issue in this case.
It seems that %b wasn't the variable causing the trouble; the discrepancy was using the %e instead of %d. When I used %d it properly extracted the date.