Getting Data In

How to write in props.conf so that the _time field takes time from the unixTime field?

gitingua
Communicator

Hello colleagues, I would like to know

I have events where there is a unixTime field. But the _time field does not show correctly

how can I write in props.conf so that the _time field takes time from the unixTime field

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gitingua,

it's possible to set a props.conf to correctly read a unixtime as timestamp.

If you could share some sample of your logs, we could help you.

Ciao.

Giuseppe

0 Karma

gitingua
Communicator

@gcuselloHi!
Снимок экрана 2022-04-22 в 13.06.36.png

as you can see, my _time field is ahead of the unixTime field. And I would need the _time field to be the same as unixTime

i want to change my sourcetype in props.conf so that _time takes time from unixTime field

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

can you add some raw data inside </> block?

Some resources to use when you are onboarding data:

Basically you should configure props.conf so, that it take correct field/place from event and recognise timestamps correct. See those TIME_*  and MAX_TIMESTAMP* for found correct place. Also LINE_BREAKER needs time by time some changes.

r. Ismo

 

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...