Splunk Enterprise

How to extract time from log

esalmon
Explorer

Hi,

I want to extract the timestamp from my log and make it the official _time in Splunk and I'm having difficulties doing that. I'd like to keep the date current as there is no date in the log files.

This is an example of what a log looks like with the Splunk time:

esalmon_0-1591835820262.png

And this is my props.conf:

esalmon_1-1591835864116.png

I just want the time in the logs to match the time in Splunk, and I am not sure what I am doing wrong. Please help

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk is Nurturing Tomorrow’s Cybersecurity Leaders Today

Meet Carol Wright. She leads the Splunk Academic Alliance program at Splunk. The Splunk Academic Alliance ...

Part 2: A Guide to Maximizing Splunk IT Service Intelligence

Welcome to the second segment of our guide. In Part 1, we covered the essentials of getting started with ITSI ...

Part 1: A Guide to Maximizing Splunk IT Service Intelligence

As modern IT environments continue to grow in complexity and speed, the ability to efficiently manage and ...