Hi,
I'm uploading multiple CSV files. Unfortunately, they don't have a usable field for the timestamp.
Is it possible to grab a part of the filename (source field) to define _time?
The structure of the filenames look like this:
"random count of signs 2015-11-01-2015-11-30.csv"
I'm thinking of a combination of strptime
and substr
, something similar to this command:
strptime((substr(source, 1, len(source)-15)), "%Y-%m-%d")
Best
Heinz
You use datetime.xml
; see link:
http://blogs.splunk.com/2009/12/02/configure-splunk-to-pull-a-date-out-of-a-non-standard-filename/
Hello. I thing this will interest you:
http://docs.splunk.com/Documentation/Splunk/6.3.1511/Data/HowSplunkextractstimestamps
http://docs.splunk.com/Documentation/Splunk/6.3.1511/Data/Configuretimestamprecognition
Thanks