Getting Data In

time formating

sbattista09
Contributor

we have a server that the time time is reporting in with an odd format,

15/May/2015:15:20:38 -0400

how would i make the stanza to get Splunk to parse this correctly to something like 05/15/2015 03:20:38 PM?

0 Karma
1 Solution

neelamssantosh
Contributor

TIME_FORMAT=%d/%b/%Y:%H:%M:%S -%3N

Hope it can help you

View solution in original post

neelamssantosh
Contributor

TIME_FORMAT=%d/%b/%Y:%H:%M:%S -%3N

Hope it can help you

Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...