Getting Data In

_time different format???

kailun92
Communicator

I have two computer running the same code and I have a set of date but all is in the format of

alt text

How can I set the time to become like this

alt text

Can someone guide me with this ?

Tags (2)
0 Karma
1 Solution

linu1988
Champion

Hello Kailun,
from your case i can tell your time is appropriately recognized from the events. You just need to re-format it.

Please follow the "Reconfigure how timestamps appear in raw data" part in the below documentation:

http://docs.splunk.com/Documentation/Splunk/5.0.4/Data/Configuretimestamprecognition

View solution in original post

linu1988
Champion

Hello Kailun,
from your case i can tell your time is appropriately recognized from the events. You just need to re-format it.

Please follow the "Reconfigure how timestamps appear in raw data" part in the below documentation:

http://docs.splunk.com/Documentation/Splunk/5.0.4/Data/Configuretimestamprecognition

gooza
Communicator
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...