I've deployed below props to extract the time splunk. There are WARN messages in splunkd logs as follows DateParserVerbose - Failed to parse timestamp in first MAX_TIMESTAMP_LOOKAHEAD (12) characters of event. Defaulting to timestamp of previous event.
please refer to the below log
Can you please help and let me know if i need to make any changes?
That looks like it should work, but here's an alternative to try:
TIME_PREFIX = \d\s+ TIME_FORMAT = %a %b %d %H:%M NO_BINARY_CHECK = true SHOULD_LINEMERGE = false