Getting Data In

timestamp field to be configured with json field data

hashsplunk
Loves-to-Learn Lots

data{ [-]
     DESCDocumentation for subsetted study data for iDAP Request INT-20200527-421
     DE_IDENTIFICATION_DATE2020-07-16
     EXCLUDED_COUNTRIESnull
     ID4849
     IS_OBSOLETEfalse
     LOCATIONroot/data_reuse/d848/d8480c00051/ar/shared/adam/doc/idap_20200716
     REMOVED_DUE_TO_COUNTRY_REMOVALnull
     REPORTING_LOCATION_ID18495
     REUSE_LOCATION_CATEGORY_ID2
     REUSE_LOCATION_DATA_CATEGORIES: [ [+]
     ]
}

I want the timestamp field to be data.DE_IDENTIFICATION_DATE to set in props.conf

INDEXED_EXTRACTIONS = JSON
TIMESTAMP_FIELDS = date
TIME_FORMAT = %Y%m%d
TZ = UTC
detect_trailing_nulls = auto
SHOULD_LINEMERGE = false
description = My source type
pulldown_type = true
disabled = false
KV_MODE = none
AUTO_KV_JSON = false
TIMESTAMP_FIELDS=DE_IDENTIFICATION_DATE

I have given above settings in my props.conf . Please suggest the write way of mentioning the json data value

Labels (1)
0 Karma

to4kawa
Ultra Champion

TIME_PREFIX = DE_IDENTIFICATION_DATE\"\s*:\s*\"

not TIMESTAMP_FIELDS=DE_IDENTIFICATION_DATE

0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...