Splunk Enterprise

Define the best sourcetype for this timestamp

leandromatperei
Path Finder

Guys.

I have the following log that I need to index in Splunk, breaking each line, what would be the best sourcetype for this log format?

 

TIME=20201031064817502 started|src=NSS|UCPU=0|SCPU=0
TIME=20201031064817506||LUSED=1|LMAX=138|OMAX=-1|LFEAT=osr_swirec,dtmf,osr_rec_tier4|UCPU=125|SCPU=31
TIME=20201031064854505 EVNT=SWIepst|VERSION=11.0.3.2019061409|UCPU=5703|SCPU=250

 

 

The format is year, month, day, hours, minutes, seconds, mseconds 

Labels (1)
Tags (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

you need to define your own sourcetype for this log format.  For time you should use in props.conf

TIME_PREFIX = TIME=
TIME_FORMAT = %Y%m%d%H%M%S%3Q

r. Ismo 

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

you need to define your own sourcetype for this log format.  For time you should use in props.conf

TIME_PREFIX = TIME=
TIME_FORMAT = %Y%m%d%H%M%S%3Q

r. Ismo 

0 Karma
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

[Puzzles] Solve, Learn, Repeat: Nested loops in Event Conversion

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...