I have structured (CSV) files with named fields with a few different date-time formats -
TIMEA,host,TIMET,DURATION,HOUR,SHIFT
01/30/2012 0:00:00,host01,1327899600,3600,0,2
TIMET (third comma-separaetd value from left) is the UNIX time. How can I force Splunk to use that as timestamp for the event?
Figured it out
TIME_FORMAT = %+
TIME_PREFIX = ^([^,]*,){2}