I have configured the TIME_FORMAT in props.conf as mentioned below.
INDEXEDEXTRACTIONS = csv
FIELDDELIMITER = ,
SHOULDLINEMERGE = false
HEADERFIELDLINENUMBER = 1
CHECKFORHEADER = true
NOBINARYCHECK = true
disabled = false
initCrcLength = 2048
CHARSET = AUTO
KVMODE = none
category = structured
description = Comma-separated value format. Set header and other settings in "Delimited Settings"
pulldowntype = 1
SEDCMD-replacespace = s/ //g
TIMESTAMPFIELDS = "TimeField"
TIME_FORMAT = %Y-%m-%d %H:%M:%S
TZ = UTC
Monitoring CSV file in UF. This props is in indexer.
Example input data - 2019-08-13 07:15:00
But after indexing _time is coming as 2019-08-13 07:00
The Minute part is disappearing.
Please suggest some solution
Hey I tried again, it's working now. Thanks a lot. But , as per the documentation, time_format and all config should be there in Indexer and not in UF
I put the props in UF and it is working fine now. Thanks
Does this mean the directory of $SPLUNK_HOME/SplunkUniversalForwarder/default
or something else?