Getting Data In

time formating

sbattista09
Contributor

we have a server that the time time is reporting in with an odd format,

15/May/2015:15:20:38 -0400

how would i make the stanza to get Splunk to parse this correctly to something like 05/15/2015 03:20:38 PM?

0 Karma
1 Solution

neelamssantosh
Contributor

TIME_FORMAT=%d/%b/%Y:%H:%M:%S -%3N

Hope it can help you

View solution in original post

neelamssantosh
Contributor

TIME_FORMAT=%d/%b/%Y:%H:%M:%S -%3N

Hope it can help you

View solution in original post