I want to extract dailyTime from XML and convert it into time
<globalView id="108" version="17" recordClassName="NormalizedEvent" retention="0" hourly="-1" hourlyTime="1284336038994" daily="-1" dailyTime="1284336038994" intervalMilliseconds="60000" writeUniqueCountersTime="0">
<criteria bop="AND">
<left>
<expr>
<interval serialization="custom">
<com.q1labs.ariel.Interval>
<short>5000</short>
<boolean>true</boolean>
<short>5000</short>
<boolean>true</boolean>
</com.q1labs.ariel.Interval>
</interval>
</expr>
<key class
Here is my props.conf
[XMLPARSING]
KV_MODE = xml
SHOULD_LINEMERGE = true
BREAK_ONLY_BEFORE = <globalView\s\w*=("\d\d\d")
MAX_EVENTS = 600
EXTRACT-dailyTime = ^(?:[^=\n]*=){8}"(\d+)
TIME_FORMAT=%s%3N
TIME_PREFIX=dailyTime=
Lookahead=13
TRUNCATE = 1000
category = Custom
disabled = false
pulldown_type = true
but splunk is not converting it
Hey
try this
TIME_PREFIX=dailyTime\D+
@ashajambagiNo not working
@chevalier51 Epoch converter shows the date to be 2010,try increasing the MAX_DAYS_AGO
TIME_FORMAT=%s%3N
TIME_PREFIX=dailyTime\D+
MAX_TIMESTAMP_LOOKAHEAD=13
MAX_DAYS_AGO=5000
Try
TIME_PREFIX=dailyTime="
@richgalloway No not working
@richgallowayYes off course