Getting Data In

How to set the timestamp format to YYYY-MM-DD?

dennisaraujo
Path Finder

I need to use the field email sent to YYYY-MM-DD format for timestamp.
How to set the timestamp for the YYYY-MM-DD format?

Thanks.

0 Karma
1 Solution

phadnett_splunk
Splunk Employee
Splunk Employee

Try using the following in props.conf for your sourcetype:
TIME_FORMAT = %Y-%m-%d

View solution in original post

phadnett_splunk
Splunk Employee
Splunk Employee

Try using the following in props.conf for your sourcetype:
TIME_FORMAT = %Y-%m-%d

dennisaraujo
Path Finder

Worked, thank you.

0 Karma

ddrillic
Ultra Champion

Maybe an example of what you are trying to do?

0 Karma

dennisaraujo
Path Finder

In the file I have the email sent field, filled with date in yyyy-mm-dd format, I use this field as a timestamp to index the file.

0 Karma

somesoni2
Revered Legend

You'd need to configure this in your props.conf for the sourcetype assigned to this data. To enable us to help you with more accurate solution, provide some sample log entries that you're trying to configure...

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...