Hey guys, I'm new to splunk and I need ur help!!!
A .log file is loaded by forwarder to Splunk and is setting the wrong timestamp like this:
Actual time
15/03/03 23:59:43.000
Events
Mon,02Mar 23:59:43 Flow Control Request counter: [1]
So I tried to set the timestamp by editing the props.conf, like this:
[palink_log]
CHARSET = CN-GB
NO_BINARY_CHECK = true
priority = 1
TIME_PREFIX = \w{3},
TIME_FORMAT = %d%b %H:%M:%S
It doesn't help and there's no year data in events. How do I set the the correct timestamp manually for this single file?
Try this TIME_FORMAT=%a,%d%b %H:%M:%S
If you do, get rid of the TIME_PREFIX, as it will conflict with the parsing of the time.
And how do I set year?