Splunk Search

Help with TIME_PREFIX

a212830
Champion

Hi,

I need some help setting up a TIME_PREFIX for the following:

INFO | jvm 1 | 2015/04/05 01:56:20 | Sametime Check: Sametime Session unloaded
INFO | jvm 1 | 2015/04/05 01:56:22 | Sametime Check: Slave thread complete; Stats:
INFO | jvm 1 | 2015/04/05 01:56:22 |

Can someone help me?

TIA.

Tags (2)
0 Karma

gfuente
Motivator

Hello

You can use this regex:

^[^\|]*\|[^\|]*\|\s*

regards

a212830
Champion

Thanks. Doesn't seem to work. Still getting "could not use strptime to parse timestamp..." messages.

Here's my entire props.conf:

ANNOTATE_PUNCT = false
KV_MODE = auto
LINE_BREAKER = ([\r\n]+)
MAX_TIMESTAMP_LOOKAHEAD = 90
NO_BINARY_CHECK = 1
SHOULD_LINEMERGE = false
TIME_PREFIX = ^[^|]|[^|]|\s*
TIME_FORMAT = %Y/%M/%d %H:%M:%S

0 Karma

gfuente
Motivator

Your time format is wrong, you should use:

%Y/%m/%d %H:%M:%S

0 Karma

a212830
Champion

Grrr. Stupid me.

Thanks!

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...