Knowledge Management

TIME_FORMET in props.conf

chvenu17
Path Finder

My csv source data file contains below timestamp . how can we convert the timestamp into TIME_FORMET representation in props.conf file

18-AUG-21 11.40.00.027 PM"

Labels (1)
0 Karma

chvenu17
Path Finder

Thanks for the reply 

 

I have tried this, for some some reason splunk ignoring %p

props.file
TIME_FORMAT=%d-%b-%y %H.%M.%S.%3N %p
MAX_TIMESTAMP_LOOKAHEAD = 24
TIME_PREFIX=^"

Sample data
DATE
"18-AUG-21 11.41.10.027 PM"

o/p from splunk
_time SAMPLE_TIME
2021-08-18 11:41:10.027 18-AUG-21 11.41.10.027 PM
2021-08-18 11:41:10.027 18-AUG-21 11.41.10.027 PM

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
please try to increase MAX_TIMESTAMP_LOOKAHEAD so it cover the whole timestamp from the beginning of line. Try e.g. 30 as if I calculate it right it must be 26 at least to cover it.
r. Ismo
0 Karma

manjunathmeti
Champion
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...