Getting Data In
Highlighted

Timestamp parsing with separate Date and Time fields

Splunk Employee
Splunk Employee

Hi there,

My event data has the following extract about 100chars in from the start of the event...

&ltdatevalue&gt2015-08-30T00:00:00&lt/datevalue&gt&lttimevalue&gt23:58:52&lt/timevalue&gt&ltagency&gtMCP&lt/agency&gt

I'm trying to get Splunk to construct the event timestamp value as 2015-08-30 23:58:52.

I've tried various forms of the following in PROPS.CONF...

TIMEFORMAT = YYYY-MM-DDT00:00:00&lt/datevalue&gt<timevalue>&lttimevalue&gtHH:MM:SS

TIMEPREFIX = &ltdatevalue&gt

Suggestions greatly appreciated.
Tony.

0 Karma
Highlighted

Re: Timestamp parsing with separate Date and Time fields

SplunkTrust
SplunkTrust

The TIME_FORMAT attribute must use strptime() metacharacters. Try this:

MAX_TIMESTAMP_LOOKAHEAD = 200
TIME_PREFIX = <date_value>
TIME_FORMAT = %Y-%m-%DT00:00:00</date_value><time_value>%H:%M:%S
---
If this reply helps you, an upvote would be appreciated.

View solution in original post

Highlighted

Re: Timestamp parsing with separate Date and Time fields

Splunk Employee
Splunk Employee

Thanks @richgalloway. Spot on.

0 Karma
Highlighted

Re: Timestamp parsing with separate Date and Time fields

Communicator

I changed the %D to %d to make this work. Thanks @richgalloway

0 Karma