Hey,
I am sure many of you, who have VPC logs on Splunk have came across this issue.
Raw Log
2 unknown eni-xxxxxxxxxxxxx 192.168.0.10 192.168.0.15 3558 6443 6 9 1196 1625657222 1625657282 ACCEPT OK
Text highlighted in red is event start_time, and I want to replace it with _time
my props.conf
[aws:cloudwatchlogs:vpcflow]
TIME_FORMAT = %s
SHOULD_LINEMERGE = false
TIME_PREFIX = ^(?>\S+\s){10}
MAX_TIMESTAMP_LOOKAHEAD = 10
Still no luck 😞
Try this
TIME_PREFIX = (\S+\s+){10}
Hello @ITWhisperer , thks for sharing. Still the same.