I have tried to get Splunk to recognize a new format of dates but im unable even to get the train date to understand the date, i only get : "Skipping unpromissing line" when running that on the logfile. The date and time is in the following format:
11032011 101305
11032011 101304
MMDDYYYY HHMMSS
I would need help to proceed to get Splunk to be able to recognize this date format.
You will need to modify the props.conf with the following (assuming 24-hour clock) :
[yoursourcetype]
TIME_FORMAT = %m%d%Y %H%M%S
Here is a link to more information:
http://docs.splunk.com/Documentation/Splunk/4.2.3/Data/Configuretimestamprecognition