Getting Data In

How to set the timestamp format to YYYY-MM-DD?

dennisaraujo
Path Finder

I need to use the field email sent to YYYY-MM-DD format for timestamp.
How to set the timestamp for the YYYY-MM-DD format?

Thanks.

0 Karma
1 Solution

phadnett_splunk
Splunk Employee
Splunk Employee

Try using the following in props.conf for your sourcetype:
TIME_FORMAT = %Y-%m-%d

View solution in original post

phadnett_splunk
Splunk Employee
Splunk Employee

Try using the following in props.conf for your sourcetype:
TIME_FORMAT = %Y-%m-%d

dennisaraujo
Path Finder

Worked, thank you.

0 Karma

ddrillic
Ultra Champion

Maybe an example of what you are trying to do?

0 Karma

dennisaraujo
Path Finder

In the file I have the email sent field, filled with date in yyyy-mm-dd format, I use this field as a timestamp to index the file.

0 Karma

somesoni2
Revered Legend

You'd need to configure this in your props.conf for the sourcetype assigned to this data. To enable us to help you with more accurate solution, provide some sample log entries that you're trying to configure...

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...