Splunk Search

Help with TIME_PREFIX

a212830
Champion

Hi,

I need some help setting up a TIME_PREFIX for the following:

INFO | jvm 1 | 2015/04/05 01:56:20 | Sametime Check: Sametime Session unloaded
INFO | jvm 1 | 2015/04/05 01:56:22 | Sametime Check: Slave thread complete; Stats:
INFO | jvm 1 | 2015/04/05 01:56:22 |

Can someone help me?

TIA.

Tags (2)
0 Karma

gfuente
Motivator

Hello

You can use this regex:

^[^\|]*\|[^\|]*\|\s*

regards

a212830
Champion

Thanks. Doesn't seem to work. Still getting "could not use strptime to parse timestamp..." messages.

Here's my entire props.conf:

ANNOTATE_PUNCT = false
KV_MODE = auto
LINE_BREAKER = ([\r\n]+)
MAX_TIMESTAMP_LOOKAHEAD = 90
NO_BINARY_CHECK = 1
SHOULD_LINEMERGE = false
TIME_PREFIX = ^[^|]|[^|]|\s*
TIME_FORMAT = %Y/%M/%d %H:%M:%S

0 Karma

gfuente
Motivator

Your time format is wrong, you should use:

%Y/%m/%d %H:%M:%S

0 Karma

a212830
Champion

Grrr. Stupid me.

Thanks!

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...