Using Splunk 4.2.4 on Windows XP
I am a newbie trying to parse my FTP logs that have time stamps that look like
04Dec11 23:54:29
So based on help from searching this great community resource, I edited F:\Program Files\Splunk\etc\users\admin\search\local\props.conf to contain
[source::F:\Shared\FTP\Log Files\*.txt]
TIME_FORMAT = %d%b%y %H:%M:%S
And restarted Splunk, (Note that I do have double back-slash in the path name but Markdown is removing them) but the parsing is still not appearing to get the correct date/time. How do I debug this?
Ok, answered this one myself... need to delete and re-index to force recognition