Getting Data In

How to extract the timestamp from source at index-time to use as _time?

power12
Communicator

Hey Splunkers ,

How can I get the splunk to use time from source and use it as _time

Following are the two files it uses.One has date and time one has only date.

 

/project/admin/sv/re/sniff/pre/logs/2022-12-16T11-57-36/status
/project/aadmin/sv/re/sniff/pre/logs/2022-12-16/status

 

HOw do I write props and transforms for it

 

Thanks in Advance

Labels (2)
0 Karma

power12
Communicator

I tried using

| eval _time=strptime(replace(source,".*logs/",""),"%Y-%m-%d")

But this only works for the one with date but not time...if I give
| eval _time=strptime(replace(source,".*logs/",""),"%Y-%m-%dT%H-%M-%S")

This works with file source which has both date and time

 

 

What can I use that works for both time formats

 

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...