Splunk Search

I have one field time received this is showing date and time i want to change with that time to _time in props .conf how it would work because i want change to _time or any other way please suggest

abhishekdubey00
Engager

FIELD -TimeReceived: 2019-05-09T05:29:03.000Z

this is my prpos .conf
xyz
SHOULD_LINEMERGE=false
NO_BINARY_CHECK=true
LINE_BREAKER = ([\r\n]+)
CHARSET=UTF-8
KV_MODE=json
TRUNCATE=999999
DATETIME_CONFIG =

Tags (1)
0 Karma

koshyk
Super Champion

is your event Starting with TimeReceived? i.e.

TimeReceived: 2019-05-09T05:29:03.000Z some other data  xxxx yyyy zzz

If yes, Please try

[your_source_type]
SHOULD_LINEMERGE=false
NO_BINARY_CHECK=true
LINE_BREAKER = ([\r\n]+)
TIME_PREFIX = ^TimeReceived:\s
TIME_FORMAT = %Y-%m-%dT%H:%M:%S

Then restart splunkd

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...