Hi,
My log event is in xml and the timestamp is in epoch format e.g. <timestamp>1399909145002</timestamp>
How can I define this in props.conf so the event timestamp will be correctly indexed in splunk?
Thanks in advance!
Well, you have a slight complication there. What you have there isn't truly epoch (number of seconds since 1/1/1970 00:00:00 GMT). What you have is the number of milliseconds.
But it appears this will work --
[test2]
TIME_PREFIX=<timestamp>
TIME_FORMAT=%s%3N
Good point!
TIME_PREFIX = \<timestamp\>
Excellent! Thanks for the upvote!
The magic works. Thank you.
If you showed me an entire XML event then I could help you with your event line breaking too.