Getting Data In

Timestamp extraction for varying subseconds and time zones?

ankithreddy777
Contributor

How do you extract a timestamp from message having

event1: Timestamp:2018-09-06T00:00:11.214000000, Timezone:UTC

event2: Timestamp:2018-09-06T00:00:11.214, Timezone:CST

where sub seconds can be milliseconds or nano seconds which vary and time zone can be any string like UTC,CST etc.

0 Karma

adonio
Ultra Champion

looks like splunk can handle it,

try below props.conf

[odd_timestamp]
SHOULD_LINEMERGE=true
NO_BINARY_CHECK=true
TIME_FORMAT=%Y-%m-%dT%H:%M:%S.%9N, Timezone:%Z
TIME_PREFIX=^
MAX_TIMESTAMP_LOOKAHEAD=48

worked for me,
see screenshot below:

alt text

sudosplunk
Motivator

If you have multiple timestamp formats in single log file, then try configuring datetime.xml. Refer to below docs for more information.

http://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Configuredatetimexml

https://www.splunk.com/blog/2014/04/23/its-that-time-again.html

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...