Getting Data In

How to extract time log from JSON data for event _time?

anantdeshpande
Path Finder

Team,

In my JSON data, there is below line which I want to be my event time (_time).

"eventDateTime" : "2017-24-08T05:19:54.500-05:00",

My props.conf has below entry. I am not sure what to write for last (-05:00). Please help.

TIME_FORMAT=%Y-%d-%mT%H:%M:%S.3N
TIME_PREFIX="eventDateTime" :

0 Karma

cmerriman
Super Champion
0 Karma

gcusello
SplunkTrust
SplunkTrust

HI anantdeshpande,
-05.00 is the timezone, put %z at the end of your TIME_FORMAT

TIME_FORMAT=%Y-%d-%mT%H:%M:%S.3N-%z

Check if brackets are in or out of your time field.

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...