Getting Data In
Highlighted

How to extract time log from JSON data for event _time?

Path Finder

Team,

In my JSON data, there is below line which I want to be my event time (_time).

"eventDateTime" : "2017-24-08T05:19:54.500-05:00",

My props.conf has below entry. I am not sure what to write for last (-05:00). Please help.

TIMEFORMAT=%Y-%d-%mT%H:%M:%S.3N
TIME
PREFIX="eventDateTime" :

0 Karma
Highlighted

Re: How to extract time log from JSON data for event _time?

Legend

HI anantdeshpande,
-05.00 is the timezone, put %z at the end of your TIME_FORMAT

TIME_FORMAT=%Y-%d-%mT%H:%M:%S.3N-%z

Check if brackets are in or out of your time field.

Bye.
Giuseppe

0 Karma
Highlighted

Re: How to extract time log from JSON data for event _time?

Super Champion
0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.