Hi,
If you want to extract timestamp from your logs (which has different formats) then you can create custom datetime.xml which will extract correct timestamp, please refer https://answers.splunk.com/answers/692340/how-can-we-set-time-format-in-propsconf-where-the.html
... View more