Security

Splunk VPC timestamp issue

General_Talos
Path Finder

Hey,

I am sure many of you, who have VPC logs on Splunk have came across this issue. 

Raw Log

2 unknown eni-xxxxxxxxxxxxx 192.168.0.10 192.168.0.15 3558 6443 6 9 1196 1625657222 1625657282 ACCEPT OK

Text highlighted in red is event start_time, and I want to replace it with _time

my props.conf

 

[aws:cloudwatchlogs:vpcflow]
TIME_FORMAT = %s
SHOULD_LINEMERGE = false
TIME_PREFIX = ^(?>\S+\s){10}
MAX_TIMESTAMP_LOOKAHEAD = 10

 

Still no luck 😞

General_Talos_0-1626263811814.png

 

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try this

TIME_PREFIX = (\S+\s+){10}
0 Karma

General_Talos
Path Finder

Hello @ITWhisperer , thks for sharing. Still the same.

0 Karma
Get Updates on the Splunk Community!

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...