Getting Data In

Splunk props.conf

yanivdutt
Explorer

Hi,
My logs are not breaking correctly. Below is sample logs

16:40:13,732 INFO web Redeemed promotion=BI_500_POINTS for usa_id=2300000032458812 channel=OMS amount=500.0 offerId=2536374313674604550 termId=null dateSk=7484 locationSk=550 isCancel=true tier=ROUGE
16:40:13,747 INFO web Redeemed promotion=ROUGE_WELCOME_KIT for usa_id=2253998837903414 channel=atg amount=-0.0 offerId=3000000000000000001 termId=null dateSk=7484 locationSk=550 isCancel=false tier=ROUGE
16:40:13,748 INFO web Redeemed promotion=BI_100_POINTS for usa_id=2253998837903414 channel=atg amount=-100.0 offerId=2536374313674604552 termId=null dateSk=7484 locationSk=550 isCancel=false tier=ROUGE
16:40:29,553 INFO web Redeemed promotion=BD_GIFT for usa_id=2300000038257945 channel=atg amount=-0.0 offerId=2536374313674604551 termId=null dateSk=7484 locationSk=550 isCancel=false tier=BI
16:40:54,421 INFO web Redeemed promotion=BD_GIFT for usa_id=2300000045716715 channel=atg amount=-0.0 offerId=2536374313674604551 termId=null dateSk=7484 locationSk=2492 isCancel=false tier=ROUGE
16:40:58,121 INFO web Redeemed promotion=VIB_WK for usa_id=2300000026110754 channel=pos amount=-0.0 offerId=2536374313674604555 termId=null dateSk=7484 locationSk=341 isCancel=false tier=BI

I tried
[web]
TIME_FORMAT=%T,%L
SHOULD_LINEMERGE=false

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi yanivdutt,
what are %T and %L?
try with

TIME_FORMAT=%H:%M:%S,%3N

I suggest to extract a sample from your logs and use the web guided log ingestion, so you can immediately test your props.

Bye.
Giuseppe

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...