Getting Data In

_JSON sourcetype indexing data - timestamp recognition

himynamesdave
Contributor

Hi all,

I am attempting to index a .json formatted file. Using the Splunk data checker, the fields are all extracted nicely using _JSON sourcetype (well done Splunk).

In my events there is a field named, "field.timestamp", that contains an epoch timestamp (13 digits) i want to use for the timestamp (no timestamp is recognised by default).

Here's a raw event:

{"field":{"timestamp":"1429306200000"}}

If I specify the field "field.timestamp" to Splunk as the field where the timestamp resides it still does not recognise any timestamp.

What would be a good way to extract this timestamp?

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

The settings actually work. If you noticed, your timestamp is in the future...

1429306200000 equates to Fri, 17 Apr 2015 21:30:00 GMT

himynamesdave
Contributor

i'm an idiot - thankyou!

0 Karma

himynamesdave
Contributor

I have also tried setting "TIME_FORMAT = %s%3N" (13 digit epoch millisecond) which also fails

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...