I'm currently monitoring a directory of CSV files with a universal forwarder (UF) that has the timestamp split across 2 fields, which isn't a problem if the time is after midday:
14-Nov-17,SOME_RANDOM_DATA,1525
Which gives me the following correct timestamp (11/14/17 3:25:00.000 PM)
However before midday the time appears in a 3 digit format:
14-Nov-17,SOME_RANDOM_DATA,740
Which should give me (11/14/17 7:40:00.000 AM), but Splunk just won't recognize the 3 digit format.
I've tried every combination of Date\Time format variables I can think of and even made an attempt at a custom datetime config but all to no avail.
I hoping I'm overlooking a simple solution but any insight anyone can offer will be greatly appreciated.
... View more