Getting Data In

How to extract time field that goes from 24:59:59 to 01:00:00?

New Member

Have a log that is confusing me on how to extract the time.

From hour 01:00:00 to 23:59:59, it's fine, but the vendor uses hour 24 instead of 0 for midnight to 1AM.

So, at 00:30:00 (12:30AM) the timestamp reads 24:30:00.

Anyone run into this or know how to recognize the 24... hour stuff as the 00... hour it should be?

Here's an actual cut and paste from the log timestamp: "24:57:05:996"

Thanks in advance,

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Index This | Why do they call it hyper text?

November 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

State of Splunk Careers 2023: Career Resilience and the Continued Value of Splunk

For the past three years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

The Great Resilience Quest: 9th Leaderboard Update

The ninth leaderboard update (11.9-11.22) for The Great Resilience Quest is out >> Kudos to all the ...