Getting Data In

_JSON sourcetype indexing data - timestamp recognition

himynamesdave
Contributor

Hi all,

I am attempting to index a .json formatted file. Using the Splunk data checker, the fields are all extracted nicely using _JSON sourcetype (well done Splunk).

In my events there is a field named, "field.timestamp", that contains an epoch timestamp (13 digits) i want to use for the timestamp (no timestamp is recognised by default).

Here's a raw event:

{"field":{"timestamp":"1429306200000"}}

If I specify the field "field.timestamp" to Splunk as the field where the timestamp resides it still does not recognise any timestamp.

What would be a good way to extract this timestamp?

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

The settings actually work. If you noticed, your timestamp is in the future...

1429306200000 equates to Fri, 17 Apr 2015 21:30:00 GMT

himynamesdave
Contributor

i'm an idiot - thankyou!

0 Karma

himynamesdave
Contributor

I have also tried setting "TIME_FORMAT = %s%3N" (13 digit epoch millisecond) which also fails

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...