Getting Data In

Date and Time Extraction from XML

danurag
Explorer

I would like to update the date and timestamp for an event during indexing.

The data is in the following format:

2012-03-05T18:21:20.533adfafadfsafsdf

The timestamp value is in GMT format and I need to convert it into PDT / PST. Splunk Server runs in PST/PDT.

Would just setting the TIME_FORMAT take care of it or do I need to set the Prefix too?

Tags (1)
0 Karma

Stephen_Sorkin
Splunk Employee
Splunk Employee

You need to set the prefix as well, since TIME_FORMAT will only look at the beginning of the line, by default:

TIME_PREFIX = <timestamp>
TIME_FORMAT = %Y-%m-%dT%T.%Q
TZ = UTC

danurag
Explorer

Thank you Steve. This helped greatly.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...