Hi,
I want to extract the timestamp from my log and make it the official _time in Splunk and I'm having difficulties doing that. I'd like to keep the date current as there is no date in the log files.
This is an example of what a log looks like with the Splunk time:
And this is my props.conf:
I just want the time in the logs to match the time in Splunk, and I am not sure what I am doing wrong. Please help