Splunk Enterprise

How to extract time from log

esalmon
Explorer

Hi,

I want to extract the timestamp from my log and make it the official _time in Splunk and I'm having difficulties doing that. I'd like to keep the date current as there is no date in the log files.

This is an example of what a log looks like with the Splunk time:

esalmon_0-1591835820262.png

And this is my props.conf:

esalmon_1-1591835864116.png

I just want the time in the logs to match the time in Splunk, and I am not sure what I am doing wrong. Please help

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...