Splunk Enterprise

How to write time format for 2022-04-07 20:40:03.360 -06:00 [XXX] XXXXX?

Hemnaath
Motivator

How to write time format for the below  event log 

2022-04-07 20:40:03.360 -06:00 [XXX] Hosting starting.
2022-04-07 20:40:03.474 -06:00 [XXX] Hosting starting.
2022-04-07 20:40:03.493 -06:00 [XXX] Hosting starting.

Getting Could not use strptime to parse the time stamp from 2022-04-07 20:40:03.360 -06:00

[Sourcetype]

SHOULD_LINEMERGE=false
LINE_BREAKER=([\r\n]+)\d+\-\d+\-\d+\s\d+\:\d+\d:\d+\.\d+\s+[^\]]+\]
NO_BINARY_CHECK=true
disabled=false
TIME_PREFIX=^
TIME_FORMAT=%Y/%m/%d %H:%M:%S.%3N %z   
MAX_TIMESTAMP_LOOKAHEAD=31

Kindly guide me to fix this time stamp issue.

Labels (2)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You're close, but the given string doesn't use the same separators as the data.  Also, a time zone with embedded ":" needs a different format character.  Try this:

TIME_FORMAT=%Y-%m-%d %H:%M:%S.%3N %:z

   

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You're close, but the given string doesn't use the same separators as the data.  Also, a time zone with embedded ":" needs a different format character.  Try this:

TIME_FORMAT=%Y-%m-%d %H:%M:%S.%3N %:z

   

---
If this reply helps you, Karma would be appreciated.
0 Karma

Hemnaath
Motivator

thanks, It fixed the error.

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...