On a monoinstance Splunk, I'd like to ingest some simple JSON data :
GDH: 2021-07-08 16:54:00.617222
I'd like to use only KV_mode, without indexed_extractions = json.
Here's my sourcetype :
LINE_BREAKER = ([\r\n]+)
SHOULD_LINEMERGE = false
TIMESTAMP_FIELDS = GDH
TIME_FORMAT = %Y-%m-%d %H:%M:%S.%6N
category = Structured
description = sourcetype - kv_mode extraction
disabled = false
pulldown_type = true
NO_BINARY_CHECK = true
Here's the result :
The event is indexed at the time of the ingestion, not the event date wich is is GDH field.
I have several sourcetypes on another environnement (clustered IDX + SH), where this positionned in props.conf on indexer cluster works fine.
Is this a consequence of the architecture being only a mono-instance ?
What did I miss ?
no luck.. same results in the UI (tried with "" and not) :
Thanks for the suggestion anyway.
Try adding TIME_PREFIX = GDH: to props.conf