Splunk Enterprise

How to write time format for 2022-04-07 20:40:03.360 -06:00 [XXX] XXXXX?

Hemnaath
Motivator

How to write time format for the below  event log 

2022-04-07 20:40:03.360 -06:00 [XXX] Hosting starting.
2022-04-07 20:40:03.474 -06:00 [XXX] Hosting starting.
2022-04-07 20:40:03.493 -06:00 [XXX] Hosting starting.

Getting Could not use strptime to parse the time stamp from 2022-04-07 20:40:03.360 -06:00

[Sourcetype]

SHOULD_LINEMERGE=false
LINE_BREAKER=([\r\n]+)\d+\-\d+\-\d+\s\d+\:\d+\d:\d+\.\d+\s+[^\]]+\]
NO_BINARY_CHECK=true
disabled=false
TIME_PREFIX=^
TIME_FORMAT=%Y/%m/%d %H:%M:%S.%3N %z   
MAX_TIMESTAMP_LOOKAHEAD=31

Kindly guide me to fix this time stamp issue.

Labels (2)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You're close, but the given string doesn't use the same separators as the data.  Also, a time zone with embedded ":" needs a different format character.  Try this:

TIME_FORMAT=%Y-%m-%d %H:%M:%S.%3N %:z

   

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You're close, but the given string doesn't use the same separators as the data.  Also, a time zone with embedded ":" needs a different format character.  Try this:

TIME_FORMAT=%Y-%m-%d %H:%M:%S.%3N %:z

   

---
If this reply helps you, Karma would be appreciated.
0 Karma

Hemnaath
Motivator

thanks, It fixed the error.

0 Karma
Get Updates on the Splunk Community!

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...