Hello,
I have to index a log file that has only the timestamp HH:MM:SS ,
HH:MM:SS field1 field2 ...
whenever a new row is added i should merge the actual date with the log timestamp YY/MM/DD HH:MM:SS .
i wasted a whole day to combining props and transforms configuration without success, Anyone can help me to solve ?
Thanks
in your props.conf, can you try setting
DETERMINE_TIMESTAMP_DATE_WITH_SYSTEM_TIME = True
How far of a skew are the event times you are looking at with the system time?
Hi @giuces,
Splunk already adds the current date to timestamp is there is no in the log. Can you describe more why your are trying to add? Maybe a sample data and props.conf will help.