- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Extracting Date Fields
sseekamp
Explorer
01-30-2012
06:23 PM
If I am doing custom field extraction on an event should I name the fields the same as the default day, month, year, time, etc or does is matter?
I hate to duplicate fields that splunk is already trying to extract or is there a way to disable the automatic date/time extraction for events? What is recommended?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
![Damien_Dallimor Damien_Dallimor](https://community.splunk.com/legacyfs/online/avatars/1760.jpg)
Damien_Dallimor
Ultra Champion
01-30-2012
07:31 PM
You could just specify your custom time extraction in props.conf
http://docs.splunk.com/Documentation/Splunk/latest/admin/propsconf
Use the TIME_FORMAT property to specify a strptime pattern for your events.
![](/skins/images/396DDBEEAC295EB5FEC41FF128E8AC0A/responsive_peak/images/icon_anonymous_message.png)