Splunk is not able to recognize the time stamp if the Min or the sec has 1 digit as in 9:2:3, but it can recognize 9:02:03. How to solve this? My problem is not with the Hour digit, but with the Min and Sec digit.
Hi this will help :
docs.splunk.com/Documentation/Splunk/6.2.2/Data/Configuretimestamprecognition
It does not, I have already ready that before posting the question. It doesn't say how to treat timestamp, if you have min and sec as single digit.