I have log files that I would like to get into Splunk but I'm having trouble due to the way the date and time are formatted in the log file. In the past I have add a few lines to the props.conf on the splunk server.
Here is what I have in the props.conf
[source::/pathtofile/logserver_output/LogServer.*] TIME_PREFIX = ^L TIME_FORMAT = %y_%m_%d.%H_%M_%S
Here is a line from the log file.
It should be "L" "year" "month" "day" "." "hour" "minute" "second".
Did I miss something? I am using a test index but it doesn't seem to be reading the date and time correctly.