Splunk Search

Easy Epoch time transformation

nkrestakos
Engager

I have a lot of DB Connect inputs connecting to MS SQL databases. a lot of the data i am pulling from these inputs have multiple date/time fields. Ususally one of the fields is my output timestamp and that will get read correctly. The other date/time fields will end up being converted by splunk to Epoch time. would i need a stanza in props.conf to address this and if so would i need to identify the fields in the stanza?

Tags (3)
0 Karma

dwaddle
SplunkTrust
SplunkTrust

If you want the other timestamp fields left alone, you can probably achieve that in SQL. You can cast the column from a TIMESTAMP type to a VARCHAR type. I would be careful, though, of timezone issues with doing this.

Alternately, you could use calculated fields to reproduce human readable times.

0 Karma

bambarit
Explorer

any tutorial for doing this one?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...