Hi,
I am printing current time in java milisecond in logs which i want to show in splunk by converting that into date.
STARTTIME=1420199729284
please help me to convert this into date.
If you're trying to parse that at index time, use this in props.conf:
TIME_FORMAT = %s%3N
If you're trying to format that into a readable date at search time, use this:
... | eval readable_date = strftime(STARTTIME/1000, "%F %T.%3N")