We have data ingesting into Splunk via HEC token, and observed the time parsing of the event is not taking properly. Example - In the event the timestamp looks like 2020-12-01 09:59:18.0674, but in the Splunk it was capturing 12/1/20 9:59:18.000 AM. Here missing the millisecond in the Splunk time but it's not limited to the millisecond.. sometimes the second field are not correct..
We tried applying the time format and time prefix for the source and sourcetype as below, but it is not fixing the issue. TIME_PREFIX = "Date": " TIME_FORMAT = %Y-%m-%d %H:%M:%S.%4N
And also tried the props.conf below;
[the_sourcetype] AUTO_KV_JSON = false INDEXED_EXTRACTIONS = json TIMESTAMP_FIELDS = Date