I am probably having a simple problem that me being a Splunk noobie is having trouble solving. I have logs that I would like to parse the datetime out of. However, since they are not a field, I think that I need to rex them and set them to a field. If this is the case. How do I do it? The logs are formatted like:
\####[2016-11-17 08:02:09.028].... <br/>
...
I would like to pull the datetime out of the log and use it as a field to filter on. How can I achieve this?
thanks in advance!
You should be able to do that using these props.conf settings.
TIME_PREFIX = ###[
TIME_FORMAT = %Y-%m-%d %H:%M:%S.%3N