Hi everyone,
Can you help me how to extract Date and Time from below XMLsample?
Here is example of a log:
I am looking for event associated timestamp (_time) will show as 2015-08-08T23:58:00
Thanks, cheers
Try this (problems in LINE_BREAKER
, TIME_PREFIX
, and TIME_FORMAT
and MAX_TIMESTAMP_LOOKAHEAD
😞
TIME_PREFIX = <date>
TIME_FORMAT = %Y-%m-%dT%H:%M:%S
MAX_TIMESTAMP_LOOKAHEAD = 19
SHOULD_LINEMERGE = False
LINE_BREAKER = (<\/row>)
TRUNCATE = 0
KV_MODE=XML
You might also check out this Q&A:
https://answers.splunk.com/answers/406376/how-do-i-edit-my-datetimexml-file-for-my-custom-da.html#an...
Whenever you modify LINE_BREAKER
, you should always use SHOULD_LINEMERGE = False
.
Also, why are you using image links instead of pasting text? Then we have to type it all in (among other annoyances and problems).
I believe the TIME_FORMAT string won't match your data because of the "T00:00:00".