Getting Data In

How to set up time_format in props.conf when only have time

jwalthour
Communicator

Splunk is indexing a log file that has a format like this:

11:03:51.319 Notify Host: HOST_STATUS_UNKNOWN {279, bdl58056}

The events can also be multi-line. So, I set up the props.conf for this sourcetype like this:

SHOULD_LINEMERGE = true
TIME_PREFIX = \d{2}:\d{2}:\d{2}\.\d{3}\s
TIME_FORMAT = %H:%M:%S.%3N
MAX_TIMESTAMP_LOOKAHEAD = 13
BREAK_ONLY_BEFORE_DATE = true

The timestamp doesn't seem to be getting picked up and assigned to _time correctly. How do I set up the event timestamp properly when the "timestamp" on the event is only the time (I can assume the date is the current date)?

Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

Change this line:

TIME_PREFIX = ^

View solution in original post

0 Karma

woodcock
Esteemed Legend

Change this line:

TIME_PREFIX = ^
0 Karma

jwalthour
Communicator

Thank you, woodcock!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...