Getting Data In

How to set the timestamp format to YYYY-MM-DD?

dennisaraujo
Path Finder

I need to use the field email sent to YYYY-MM-DD format for timestamp.
How to set the timestamp for the YYYY-MM-DD format?

Thanks.

0 Karma
1 Solution

phadnett_splunk
Splunk Employee
Splunk Employee

Try using the following in props.conf for your sourcetype:
TIME_FORMAT = %Y-%m-%d

View solution in original post

phadnett_splunk
Splunk Employee
Splunk Employee

Try using the following in props.conf for your sourcetype:
TIME_FORMAT = %Y-%m-%d

dennisaraujo
Path Finder

Worked, thank you.

0 Karma

ddrillic
Ultra Champion

Maybe an example of what you are trying to do?

0 Karma

dennisaraujo
Path Finder

In the file I have the email sent field, filled with date in yyyy-mm-dd format, I use this field as a timestamp to index the file.

0 Karma

somesoni2
Revered Legend

You'd need to configure this in your props.conf for the sourcetype assigned to this data. To enable us to help you with more accurate solution, provide some sample log entries that you're trying to configure...

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...