I have date and time in this format,
How to read it correctly into Splunk?
Give this a try (props.conf on your indexer/heavy forwarder)
....other line breaking stuffs...
TIME_PREFIX = \[
TIME_FORMAT = %Y/%m/%d@%H:%M:%S.%3N%z
MAX_TIMESTAMP_LOOKAHEAD = 28
View solution in original post