Hello, how can I write TIME_PREFIX for props conf file for following sample event. Any help will be highly appreciated. Thank you, greatly appreciated.
INFORMATION:Metadata Deployment process started at Tue Jun 16 11:51:47 EDT 2020.
INFORMATION:Metadata Deployment process ended at Tue Jun 16 11:51:48 EDT 2020.
INFORMATION:Metadata Deployment process ended at Tue Jun 16 11:51:49 EDT 2020
@SplunkDash Try this works only for sample events provided having fixed spaces and Alpha-numeric.
TIME_PREFIX = ^INFORMATION:\w+\s\w+\s\w+\s+\w+\s\w+\s
---
An upvote would be appreciated if this reply helps!
Thank you so much appreciated. What about if I use
TIME_PREFIX=at+\s
Since # of words are not the same, but there always "at+\s" before the Date/Time. But, please let me know if you have any recommendation other than this.