I have two computer running the same code and I have a set of date but all is in the format of
How can I set the time to become like this
Can someone guide me with this ?
Hello Kailun,
from your case i can tell your time is appropriately recognized from the events. You just need to re-format it.
Please follow the "Reconfigure how timestamps appear in raw data" part in the below documentation:
http://docs.splunk.com/Documentation/Splunk/5.0.4/Data/Configuretimestamprecognition
Hello Kailun,
from your case i can tell your time is appropriately recognized from the events. You just need to re-format it.
Please follow the "Reconfigure how timestamps appear in raw data" part in the below documentation:
http://docs.splunk.com/Documentation/Splunk/5.0.4/Data/Configuretimestamprecognition
change the URL https://mysplunk:8000/en-US/
Modify props.conf, these links may help you
http://docs.splunk.com/Documentation/Splunk/5.0.4/admin/Propsconf
http://docs.splunk.com/Documentation/Splunk/5.0.4/Data/Configuretimestamprecognition