Getting Data In

timestamp field to be configured with json field data

hashsplunk
Loves-to-Learn Lots

data{ [-]
     DESCDocumentation for subsetted study data for iDAP Request INT-20200527-421
     DE_IDENTIFICATION_DATE2020-07-16
     EXCLUDED_COUNTRIESnull
     ID4849
     IS_OBSOLETEfalse
     LOCATIONroot/data_reuse/d848/d8480c00051/ar/shared/adam/doc/idap_20200716
     REMOVED_DUE_TO_COUNTRY_REMOVALnull
     REPORTING_LOCATION_ID18495
     REUSE_LOCATION_CATEGORY_ID2
     REUSE_LOCATION_DATA_CATEGORIES: [ [+]
     ]
}

I want the timestamp field to be data.DE_IDENTIFICATION_DATE to set in props.conf

INDEXED_EXTRACTIONS = JSON
TIMESTAMP_FIELDS = date
TIME_FORMAT = %Y%m%d
TZ = UTC
detect_trailing_nulls = auto
SHOULD_LINEMERGE = false
description = My source type
pulldown_type = true
disabled = false
KV_MODE = none
AUTO_KV_JSON = false
TIMESTAMP_FIELDS=DE_IDENTIFICATION_DATE

I have given above settings in my props.conf . Please suggest the write way of mentioning the json data value

Labels (1)
0 Karma

to4kawa
Ultra Champion

TIME_PREFIX = DE_IDENTIFICATION_DATE\"\s*:\s*\"

not TIMESTAMP_FIELDS=DE_IDENTIFICATION_DATE

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...