Splunk Cloud Platform

Timestamp format

supreme_coder
Engager

I have a timestamp like this "2020-Jan-01 21:59"

When I ingest data, I want this timestamp field to be registered as _time field in splunk

What is the right striptime() string to use to parse this my timestamp?

 

supreme_coder_0-1612363421493.png

supreme_coder_1-1612363500788.png

 

 

Labels (2)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Looks like "%Y-%b-%d %H:%M"

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Looks like "%Y-%b-%d %H:%M"

Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...