I am new to Splunk so please forgive me for what I do not know. We are getting events with start=1661359208771 and need to covert it to a readable timestamp. I have tried changing the below Timestamp format and prefix with no luck. Any suggestions?
You had the right TIME_FORMAT the first time. These settings should do it.
TIME_PREFIX = start=
TIME_FORMAT = %s%3N
If you need to experiment with ingest settings, try using the Add Data wizard.
View solution in original post