My data set has time in the format 10/1/2015 12:02:00 AM in a single _time field. would anyone be able to tell me the correct strptime in importing the data.
In that case the time format should be %m/%d/%Y %I:%M:%S %p
.
http://docs.splunk.com/Documentation/Splunk/6.3.3/SearchReference/Commontimeformatvariables
In that case the time format should be %m/%d/%Y %I:%M:%S %p
.
http://docs.splunk.com/Documentation/Splunk/6.3.3/SearchReference/Commontimeformatvariables
Is that January 10th or October 1st?
october 1st