Getting Data In

JSON AN HTTP Event Collector

New Member

How do you extract a timestamp from JSON logs that are being sent to an HTTP Event Collector?

What solution can you give me to be able to extract the JSON programming time.
alt text

0 Karma


Hello @isabel09,

please find below a working example :

| makeresults 
| eval _raw="{\"ENDTIME\":\"05/08/2019 17:36\",\"JOBCODE\":\"DAY_END_JOB\",\"STARTTIME\":\"05/08/2019 17:31\",\"STATUS\":\"COMPLETED\"}"
| spath
| eval _time=strptime(STARTTIME,"%d/%m/%Y %H:%M")
0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes and swag!