Searching for the other answer, I believe this is one of the most common questions, but I couldn't figure out my answer after reading all the others. So here it goes:
My CSV looks like this:
trig.hwts,delta
1517492760549648185,58445
And after setting the options via splunk web interface, here is what my props.conf looks like:
[csv]
DATETIME_CONFIG =
NO_BINARY_CHECK = true
TIMESTAMP_FIELDS = trig_hwts
disabled = false
TIME_FORMAT = %s%9N
TZ = America/Detroit
Note that I have specified TIMESTAMP_FIELDS as trig_hwts (_ instead of the . ) because that is how splunk recognized this field. (I have tried changing it to . as well, but that also didn't work)
The problem is splunk is not picking trig.hwts at all. It keeps showing the time when I uploaded my file to splunk, and not the time in the file. I have restarted my splunk after editing file.
Any help is appreciated.
... View more