Hi there,
My event data has the following extract about 100chars in from the start of the event...
<date_value>2015-08-30T00:00:00</date_value><time_value>23:58:52</time_value><agency>MCP</agency>
I'm trying to get Splunk to construct the event timestamp value as 2015-08-30 23:58:52.
I've tried various forms of the following in PROPS.CONF...
TIME_FORMAT = YYYY-MM-DDT00:00:00</date_value><time_value><time_value>HH:MM:SS
TIME_PREFIX = <date_value>
Suggestions greatly appreciated.
Tony.
The TIME_FORMAT attribute must use strptime() metacharacters. Try this:
MAX_TIMESTAMP_LOOKAHEAD = 200
TIME_PREFIX = <date_value>
TIME_FORMAT = %Y-%m-%DT00:00:00</date_value><time_value>%H:%M:%S
The TIME_FORMAT attribute must use strptime() metacharacters. Try this:
MAX_TIMESTAMP_LOOKAHEAD = 200
TIME_PREFIX = <date_value>
TIME_FORMAT = %Y-%m-%DT00:00:00</date_value><time_value>%H:%M:%S
I changed the %D to %d to make this work. Thanks @richgalloway
Thanks @richgalloway. Spot on.