Getting Data In

Timestamp configuration in props for epoch time

Tamilraj28
Engager

Dear All,

I am getting data from the Search head in json format. The first field of the event is timestamp and it is in epoch time format("timestamp": 1609414219738696) with 16 digits.

My problem is i need to onboard data with _time value from timestamp field. So in props.conf file of Cluster master i updated as below

TIMESTAMP_FIELDS = timestamp
TIME_FORMAT = %s%6N

But the _time field is not populated properly . And i am getting 2 values in indexed data for timestamp field as below.

timestamp.PNG

Please help me on this 

Labels (5)
0 Karma

anwarmian
Communicator

Hello Tamilraj28,
You may have already found your solution, but here is one.
Since it is a json file and not a csv, and the timestamp needs to be extracted before the json  fields are available you need to use TIME_PREFIX not TIMESTAMP_FIELDS. in your case you need to add:

TIME_PREFIX = timestamp":

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...