Getting Data In

Timestamp recognition when date appears once but time appears on every line

jbesant
Explorer

Hi, I can't seem to work out how to do this. I've looked in the documentation but can't find an example. I am trying to set up date/time recognition for a log file that has the date only on the first line of the log file and then every entry thereafter has the time. Here is an example:

Logfile name xxxxx Current Day: 01/30/2021

(13:11:06.696)(07059)ABCDEF_01: TX (000)162,47773,455,0538,126,00152,00174|00000
(13:11:07.324)(07060)ABCDEF_01: RX (000)162,47773,455,0538,126,00152,00174|00000

 How do I define the extraction so every event has the date 01/30/2021 and then the time of the event is taken from every line as H:%M:%S.%3N %Z

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...