Hi -
I have a quick props question.
I need to write a props for a particular sourcetype, and the messages always start with before the timestamp starts:
ukdc2-pc-sfn122.test.local - OR ukdc2-pc-sfn121.test.local -
When writing the TIME_PREFIX can a regex be written to account for this, is it just a basic one if so can someone provide this?
Thanks
Hi @tomjb94 ,
could you share some sample of your logs?
Anyway, if in your logs there's only one timestamp, you could try to use only TIME_FORMAT without TIME_PREFIX.
ciao.
Giuseppe