hi,
I would like extract the timezone offset in time format in props.
example time format , 2017-02-05T01:20:10.049-0500: 0.855:
TIME_FORMAT = %Y-%m-%dT%H:%M:%S.%3N-%Z
But the above timeformat which i defined is not working. I want my timestamp in splunk to have upto 2017-02-05T01:20:10.049-0500 ignoring 0.855
%Y-%m-%dT%H:%M:%S.%3N%Z
thank you for reply but it is not working.
This needs to be deployed to your indexers and splunkd restarted there and even then only events that are indexed post-restart will show the effects of the new configurations.
I see that this is accepted; so is it working now?