I have to index a log file that has only the timestamp HH:MM:SS ,
HH:MM:SS field1 field2 ...
whenever a new row is added i should merge the actual date with the log timestamp YY/MM/DD HH:MM:SS .
i wasted a whole day to combining props and transforms configuration without success, Anyone can help me to solve ?
in your props.conf, can you try setting
DETERMINE_TIMESTAMP_DATE_WITH_SYSTEM_TIME = True
How far of a skew are the event times you are looking at with the system time?
Splunk already adds the current date to timestamp is there is no in the log. Can you describe more why your are trying to add? Maybe a sample data and props.conf will help.