SYSLOG often sends the timestamp in the older format (e.g. Jul 11 14:23:32). Unfortunately, that format does not have a year or timezone. I know that Splunk has logic to 'figure' it out, but I need to have it reformatted to the following:
Is there a way to accomplish this with INGEST_EVAL or other method? If so how is it done? This should change the _raw event(that is, this is not a search time question). Kind of like a mask.