Splunk Search

Timestamp creation- index time from csv file

sidhantbhayana
Path Finder

Hi All,

I have a situation where the data is in csv format and first two columns have date and time information, my requirement is to create _time using both columns during indexing.

Sample Logs:
012518,12:34:41:163,1
012618,16:04:42:100,10

I am facing problems in creating configs for the same.

_
Regards,
Sidhant

Tags (1)
0 Karma
1 Solution

mayurr98
Super Champion

hey,

Just assign below in inputs.conf wherever your monitor stanza is!

[<your_monitor_stanza>]
index = <your_index>
sourcetype = csv

Let me know if this helps!

View solution in original post

0 Karma

mayurr98
Super Champion

hey,

Just assign below in inputs.conf wherever your monitor stanza is!

[<your_monitor_stanza>]
index = <your_index>
sourcetype = csv

Let me know if this helps!

0 Karma

sidhantbhayana
Path Finder

It helps @mayurr98 , but I have a custom sourcetype, although I could find the solution: TIME_FORMAT=%m%d%y,%H:%M:%S:%3N

0 Karma

mayurr98
Super Champion

yeah, if you have a custom sourcetype then TIME_FORMAT=%m%d%y,%H:%M:%S:%3N this would do!

0 Karma

HiroshiSatoh
Champion
DATE,TIME,COUNT
012518,12:34:41:163,1
012618,16:04:42:100,10

Can you retrieve it with data source CSV? In my environment _time has been set without any particular settings.

0 Karma

sidhantbhayana
Path Finder

Yes, correct! This is because you are using default sourcetype(csv). I have a custom sourcetype.

0 Karma
Get Updates on the Splunk Community!

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...

4 Ways the Splunk Community Helps You Prepare for .conf25

.conf25 is right around the corner, and whether you’re a first-time attendee or a seasoned Splunker, the ...