Splunk Search

logfile with timestamp but no date

a212830
Champion

Hi,

I have a logfile with a timestamp, but no date, being processed by a universal forwarder. How should I handle this?

Tags (1)
0 Karma

wrangler2x
Motivator

information on how Splunk assigns timestamps may be found here: http://docs.splunk.com/Documentation/Splunk/latest/Data/HowSplunkextractstimestamps

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!