I'm running into an issue with Splunk ignoring the timestamp in a specific log and just using current indexing time. Example extract(XXXX and #### replace letters and numbers)
[2011-09-27-04-03-54][XXXX::IA::Actions][####]: BUYER_EMAIL_INVOICES_ADDRESS: []
[2011-09-27-04-03-54][XXXX::IA::Actions][####]: BUYER_LANGUAGE_ID: [25]
[2011-09-27-04-03-54][XXXX::IA::Actions][####]: BUYER_DATE_FORMAT_ID: [1]
Format is %Y-%m-%d-%H-%M-%S
I've attempted the below dateformat to resolve this (there is a backslash escaping the [ below, it's being removed):
TIME_PREFIX = [
TIME_FORMAT = %Y-%m-%d-%H-%M-%S
Unfortunately, no luck, and it's still showing up with the indexing time.
Any help on this? I'm running into a wall.
... View more