Splunk Search

Help with TIME_PREFIX

a212830
Champion

Hi,

I need some help setting up a TIME_PREFIX for the following:

INFO | jvm 1 | 2015/04/05 01:56:20 | Sametime Check: Sametime Session unloaded
INFO | jvm 1 | 2015/04/05 01:56:22 | Sametime Check: Slave thread complete; Stats:
INFO | jvm 1 | 2015/04/05 01:56:22 |

Can someone help me?

TIA.

Tags (2)
0 Karma

gfuente
Motivator

Hello

You can use this regex:

^[^\|]*\|[^\|]*\|\s*

regards

a212830
Champion

Thanks. Doesn't seem to work. Still getting "could not use strptime to parse timestamp..." messages.

Here's my entire props.conf:

ANNOTATE_PUNCT = false
KV_MODE = auto
LINE_BREAKER = ([\r\n]+)
MAX_TIMESTAMP_LOOKAHEAD = 90
NO_BINARY_CHECK = 1
SHOULD_LINEMERGE = false
TIME_PREFIX = ^[^|]|[^|]|\s*
TIME_FORMAT = %Y/%M/%d %H:%M:%S

0 Karma

gfuente
Motivator

Your time format is wrong, you should use:

%Y/%m/%d %H:%M:%S

0 Karma

a212830
Champion

Grrr. Stupid me.

Thanks!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...