Getting Data In

Splunk line breaking issue

knalla
Path Finder

Hi, I'm trying to line break events and extract time stamp, but it has no date any ideas how to get this?

[04:05:16.255][t] setting data time stamp

[04:05:14.255][t] setting data time stampwewe22

[04:05:12.255][t] setting data time etc

 <PSET>CDPTLSGSG <cc>

Labels (2)
0 Karma

The_Simko
Path Finder

Good day Knalla,  

If the logs are from the current day, then you are in luck:  
in props:
TIME_FORMAT=\d{2}:\d{2}:\d{2}\.\d{3}
TIME_PREFIX=^\[
MAX_TIMESTAMP_LOOKAHEAD=25

Now, if the logs aren't from the given day you'll have to do something like store the logs in a directory with the date.  then use the above props and you can bring in data 

Good luck!

Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...