How to extract timestamp( is in bold text ) from the below event inside a file. Attached the source file. Each file content is considered as single event. currently it is taking file modification time as timestamp of the event. how to prevent this.
20150121
1
082142
08:21:42:379
99324
admin2
emergencey.2
0
xyz.23015521
too many times
150121082142379
see http://docs.splunk.com/Documentation/Splunk/latest/Data/Handleeventtimestamps
using TIME_FORMAT = %d%m%Y%H%M%S
should do the trick
well the TIME_format is certainly wrong, what format is 150121082142379 seconds since the epoc seems not to fit as well
I tried with TIME_FORMAT. But it is not working.