Monitoring Splunk

Splunk not storing time in milliseconds

ankith_nt
New Member

I am extracting the timestamp from events in microseconds (%Y-%m-%d:%H:%M:%S.%6N). But when index event timestamp is not showing in sub seconds. Always I see zeroth subsecond in timestamp. Is there any overwritten possible other than by props?

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

I think this is just a question of how Splunk shows _time. Try something like this to see if it helps.

<YOUR BASE SEARCH> 
| convert timeformat="%Y-%m-%d %H:%M:%S:%6N" ctime(_time) AS c_time 
| table c_time
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...