Getting Data In

time formating

sbattista09
Contributor

we have a server that the time time is reporting in with an odd format,

15/May/2015:15:20:38 -0400

how would i make the stanza to get Splunk to parse this correctly to something like 05/15/2015 03:20:38 PM?

0 Karma
1 Solution

neelamssantosh
Contributor

TIME_FORMAT=%d/%b/%Y:%H:%M:%S -%3N

Hope it can help you

View solution in original post

neelamssantosh
Contributor

TIME_FORMAT=%d/%b/%Y:%H:%M:%S -%3N

Hope it can help you

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...