I am trying to extract the _time from the log
Jul 28 12:00:49 104.128.100.1 420391: Jul 28 06:30:25.023: %Sample: Sample: cp : QFP:0.0
but the Splunk is extracting the _time as 2022-07-28T12:00:49.000+05:30 I want it to extract the second time from log i.e Jul 28 06:30:25.023
i tried the approach
In props.conf file added
but not able to extract can someone pls help
Jul 28 12:00:49 104.128.100.1
This is the string from which Splunk tries to parse out the timestamp.
Increase your MAX_TIMESTAMP_LOOKAHEAD
Hi @sagarpatil09,
please try this options:
[your_sourcetype]
TIME_PREFIX = :\s+
TIME_FORMAT = %b %d %H:%M:%S.%3N
Ciao.
Giuseppe