Getting Data In

_time different format???

kailun92
Communicator

I have two computer running the same code and I have a set of date but all is in the format of

alt text

How can I set the time to become like this

alt text

Can someone guide me with this ?

Tags (2)
0 Karma
1 Solution

linu1988
Champion

Hello Kailun,
from your case i can tell your time is appropriately recognized from the events. You just need to re-format it.

Please follow the "Reconfigure how timestamps appear in raw data" part in the below documentation:

http://docs.splunk.com/Documentation/Splunk/5.0.4/Data/Configuretimestamprecognition

View solution in original post

linu1988
Champion

Hello Kailun,
from your case i can tell your time is appropriately recognized from the events. You just need to re-format it.

Please follow the "Reconfigure how timestamps appear in raw data" part in the below documentation:

http://docs.splunk.com/Documentation/Splunk/5.0.4/Data/Configuretimestamprecognition

gooza
Communicator
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...