Hello!
I can't manage to get Splunk to extract the following timestamp at import.
2015-12-01 00:00:00+00
Could you help me finding the format string required for proper extraction?
Thanks!
It would help to know what you've tried so far and how those attempts have failed.
Have you tried %Y-%m-%d %H:%M:%S%:::z ?
Once parsed, you'll still have a problem with Splunk accepting the date because it's so old. By default, dates up to 5 years ago are accepted. Change the MAX_DAYS_AGO setting in props.conf to allow older dates.