How to write the extract the timestamp from the following event in props.conf?
Mar 3 15:16:10 servername user:info syslog.........
Add these to your props.conf
[yoursourcetype]
....other line breaking stuffs...
TIME_PREFIX = ^
TIME_FORMAT = %b %d %H:%M:%S
MAX_TIMESTAMP_LOOKAHEAD = 15
Add these to your props.conf
[yoursourcetype]
....other line breaking stuffs...
TIME_PREFIX = ^
TIME_FORMAT = %b %d %H:%M:%S
MAX_TIMESTAMP_LOOKAHEAD = 15