Getting Data In

How to set the timestamp format to YYYY-MM-DD?

Path Finder

I need to use the field email sent to YYYY-MM-DD format for timestamp.
How to set the timestamp for the YYYY-MM-DD format?

Thanks.

0 Karma
1 Solution

Splunk Employee
Splunk Employee

Try using the following in props.conf for your sourcetype:
TIME_FORMAT = %Y-%m-%d

View solution in original post

Splunk Employee
Splunk Employee

Try using the following in props.conf for your sourcetype:
TIME_FORMAT = %Y-%m-%d

View solution in original post

Path Finder

Worked, thank you.

0 Karma

Ultra Champion

Maybe an example of what you are trying to do?

0 Karma

Path Finder

In the file I have the email sent field, filled with date in yyyy-mm-dd format, I use this field as a timestamp to index the file.

0 Karma

SplunkTrust
SplunkTrust

You'd need to configure this in your props.conf for the sourcetype assigned to this data. To enable us to help you with more accurate solution, provide some sample log entries that you're trying to configure...

0 Karma