Getting Data In

How to parse the date_time and event_time fields from my raw data in PSV format?

Path Finder


i have some mainframe logs coming into splunk which is in PSV (pipe separated value) format. have managed to parse all of the data successfully, but the date_time and Event_time fields are showing dates as 31 dec, 1969 and 1970, but in the log file, it's dated april to june of 2015.

sample log:

0 Karma

Esteemed Legend

You need to tell Splunk how to interpret the timestamp in each event as documented here:

Just by looking at your event, I have no idea how to interpret your timestamps so I assume Splunk is treating them as epoch which is giving a time way in the past.

0 Karma