Today I've been trying to index a logfile in which only the timefield hours is given. I tried several ways to import this in the right manner, but I can't seem to get it to work.. Does anybody know how Splunk would be able to index this logfile correctly?
Here is one line from the log. The first element is the date field (here: 2016-12-01), where the second is the hour field (here: 0)
Thank you so much. I've been trying to find out how this works for quite a while now. Do you maybe have any documentation about how to construct such source types? (especially how to build up the LINEBREAKER component and why TIMEPREFIX=^)