Splunk Search

TIME_PREFIX props question

tomjb94
Observer

Hi - 

I have a quick props question.

I need to write a props for a particular sourcetype, and the messages always start with before the timestamp starts:

ukdc2-pc-sfn122.test.local - OR ukdc2-pc-sfn121.test.local - 

When writing the TIME_PREFIX can a regex be written to account for this, is it just a basic one if so can someone provide this?

Thanks

 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @tomjb94 ,

could you share some sample of your logs?

Anyway, if in your logs there's only one timestamp, you could try to use only TIME_FORMAT without TIME_PREFIX.

ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...