Getting Data In

How to set up time_format in props.conf when only have time

jwalthour
Communicator

Splunk is indexing a log file that has a format like this:

11:03:51.319 Notify Host: HOST_STATUS_UNKNOWN {279, bdl58056}

The events can also be multi-line. So, I set up the props.conf for this sourcetype like this:

SHOULD_LINEMERGE = true
TIME_PREFIX = \d{2}:\d{2}:\d{2}\.\d{3}\s
TIME_FORMAT = %H:%M:%S.%3N
MAX_TIMESTAMP_LOOKAHEAD = 13
BREAK_ONLY_BEFORE_DATE = true

The timestamp doesn't seem to be getting picked up and assigned to _time correctly. How do I set up the event timestamp properly when the "timestamp" on the event is only the time (I can assume the date is the current date)?

Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

Change this line:

TIME_PREFIX = ^

View solution in original post

0 Karma

woodcock
Esteemed Legend

Change this line:

TIME_PREFIX = ^
0 Karma

jwalthour
Communicator

Thank you, woodcock!

0 Karma
Get Updates on the Splunk Community!

Splunk Certification Support Alert | Pearson VUE Outage

Splunk Certification holders and candidates!  Please be advised of an upcoming system maintenance period for ...

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...