Hi,
How would I write Time_FORMAT and TIME_PREFIX for my Props Conf file for the following sample events. Any help will be highly appreciated. Thank you so much.
RTJCB|DEMOEE|AFFR|ANALYST |VIEWSUMMARY |XYA565656873 ||12.214.61.90|00| |20210730 13:00:26:907| |000000|030|ACMF|0| STJCB|DEMOEE|AFFR|ANALYST |VIEWCASE |YNA565656873 ||12.214.61.90|00| |20210730 13:00:29:045| |000000|030|ACMF|0| TRJCB|DEMO|AFFR|ANALYST |VIEWSUMMARY |XBC565656873 ||12.214.61.90|00| |20210730 13:00:30:421| |000000|030|ACMF|0| RXJCB|DEMOEE|AFFR|ANALYST |VIEWCASE |DCN132748456 ||12.214.61.90|00| |20210730 13:00:40:273| |201512|030|ACMF|0| DSJCB|DEMOEE|AFFR|ANALYST |UPDATECASE |CBB132748456 ||12.214.61.90|01|Attempt to update to an code |20210730 13:00:47:347| |201512|030|ACMF|0|
RXJCB|DEMOEE|AFFR|ANALYST |VIEWCASE |ABB132748456 ||12.214.61.90|00| |20210730 13:00:48:519| |201512|030|ACMF|0|
Format based on your data is
%Y%m%d %H:%M:%S:%Q
and prefix is
([^\|]*\|){10}
which is looking for the 10th PIPE symbol in the data
Thank you so much, appreciated
I used this one as well. Only problem when I use this double pipe "||". If I use {9} without this "||" (i.e, replace "||" with "|") working as expected, but, getting error message when I have "||" in the events. Any help will be highly appreciated.
I think I am good, working as expected. Thank you again, truly appreciated your support in this effort.