Below is our csv log sample, and so far the following is working for us at the UF level -
INDEXED_EXTRACTIONS = csv
FIELD_NAMES=Account_Number, Amount, Origin, Transaction_Code, Transaction_Date, Transaction_TimeI would like to extract the time from the last two fields, how do I go about this?
0100000000003015044732,000000000006000,00900,1701,091326,220913
I've never had a similar case but browsing through the docs I'd say that while the most obvious first thing to try would be to use TIME_PREFIX and "count commas" up to your date and time fields (and then use appropriate TIME_FORMAT to parse it), that might not work well with all possible commas embedded in strings, possible escaped quotes and so on (I always say that brute-forcing structured data with a plain regex is a bad idea).
So, judging from past discussions on Slack it seems my interpretation of the docs were right - when you're using indexed extractions and specify TIMESTAMP_FIELDS, Splunk concatenates them together.
So with your example you'd get Transaction_Date=091326 and Transaction_Time=220913 parsed from your event.
If you use
TIMESTAMP_FIELDS=Transaction_Date,Transaction_time
Splunk will use the 091326220913 value for time parsing.
Now you only need a proper TIME_FORMAT to parse it. I believe it would be something like
TIME_FORMAT= %y%m%d%H%M%S
As always, be wary about timezone since your timestamp doesn't seem to include it.
TIMESTAMP_FIELDS=Transaction_Date,Transaction_time
TIME_FORMAT= %y%m%d%H%M%S
Worked perfectly fine on a stand-alone instance, would it work on a UF?
It should. Timestamp extraction with indexed extractions is happening on the source UF so that's where you need those settings.
BTW, verify that TIME_FORMAT - as @livehybrid pointed out, your example included americanized time format (m/d/y) whereas I used y/m/d
I would agree largely with @PickleRick although I think the TIME_FORMAT should be
TIME_FORMAT=%m%d%y%H%M%Sbecause the sample 091326 is MMDDYY.
🌟Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing.
Ahhh, right you are. I didn't notice the non-existent month 😉