Getting Data In

timestamp field to be configured with json field data

hashsplunk
Loves-to-Learn Lots

data{ [-]
     DESCDocumentation for subsetted study data for iDAP Request INT-20200527-421
     DE_IDENTIFICATION_DATE2020-07-16
     EXCLUDED_COUNTRIESnull
     ID4849
     IS_OBSOLETEfalse
     LOCATIONroot/data_reuse/d848/d8480c00051/ar/shared/adam/doc/idap_20200716
     REMOVED_DUE_TO_COUNTRY_REMOVALnull
     REPORTING_LOCATION_ID18495
     REUSE_LOCATION_CATEGORY_ID2
     REUSE_LOCATION_DATA_CATEGORIES: [ [+]
     ]
}

I want the timestamp field to be data.DE_IDENTIFICATION_DATE to set in props.conf

INDEXED_EXTRACTIONS = JSON
TIMESTAMP_FIELDS = date
TIME_FORMAT = %Y%m%d
TZ = UTC
detect_trailing_nulls = auto
SHOULD_LINEMERGE = false
description = My source type
pulldown_type = true
disabled = false
KV_MODE = none
AUTO_KV_JSON = false
TIMESTAMP_FIELDS=DE_IDENTIFICATION_DATE

I have given above settings in my props.conf . Please suggest the write way of mentioning the json data value

Labels (1)
0 Karma

to4kawa
Ultra Champion

TIME_PREFIX = DE_IDENTIFICATION_DATE\"\s*:\s*\"

not TIMESTAMP_FIELDS=DE_IDENTIFICATION_DATE

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...