Splunk Search

How to convert hex timestamp value to index in Splunk

smdasim
Explorer

Hi ,

I have the below data to index into splunk

Can you advice how can i decode the hex timestamp below (5A8145B4.0000) so that below events can be indexed into splunk
via inputs.conf/props.conf

+5A8145B4.0000 Component: kbb
+5A8145B4.0000 Driver: tms_ctbs623fp5:d4009a/4402680.1

(5A8145B4.0004-1:kbbssge.c,52,"BSS1_GetEnv") KMS_NODEID="huhhjyxphtm01bvgfdx2"
(5A8145B4.0005-1:kbbssge.c,52,"BSS1_GetEnv") KMS_NODEID="jhgfklhtm01bnhbx2"
(5A8145B4.0006-1:kbbssge.c,52,"BSS1_GetEnv")

many thanks
smdasim

Tags (1)
0 Karma
Get Updates on the Splunk Community!

ATTENTION!! We’re MOVING (not really)

Hey, all! In an effort to keep this Slack workspace secure and also to make our new members' experience easy, ...

Splunk Admins: Build a Smarter Stack with These Must-See .conf25 Sessions

  Whether you're running a complex Splunk deployment or just getting your bearings as a new admin, .conf25 ...

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...