I'm having trouble extracting the following timestamp for one source, is there someone here that can recommend what values to put into the $SPLUNK_HOME/etc/system/default/local file under the TIME_FORMAT attribute?
Dec 3 2019 12:59AM
I have set TIME_FORMAT to be %b %#d %Y %l:%M%p but it is ignoring the AM or PM
I am getting an error could not use strptime to parse timestamp from | xyz.com | 94 | 2051 | 436 | 0 | 21 | | Dec 3 2019 12:59AM | destructive |
and it is returning this is the timestamp 12/3/19 12:59:00.000 PM