How do I get splunk to show the date and time correctly based on the event?For example if I have the following event from oracle logs:
RETURNCODE=0,OS_PROCESS=1671350,EXTENDED_TIMESTAMP="22/07/10 12:55:50.251291 PM +08:00",TO_CHAR(EXTENDED_TIMESTAMP,'MM="07/22/2010 12:55:50",OS_USERNAME=,USERNAME=,USERHOST=,OBJ_NAME=,SCN=,ACTION=,TRANSACTIONID=,ACTION_NAME=""
Splunk is displaying the incorrect date as:
Some events may translate with incorrect time as well.
Have tried using "DATETIME config=current" in props.conf,but still there is a time differences as the splunk and oracle server time is not in sync.
asked 22 Jul '10, 06:30
remy you can try something like this:
Here are the docs on this, read them for more knowledge on how to deal with this: Configure Timestamp Recognition
answered 22 Jul '10, 06:55