I have a log file where i need to do a Timestamp extraction which is in the middle of the log....
somehow it's capturing 2017 8:09:16 PM Is R
(from the next line)
NewStatServer ----------------------------------
Started Time: 3/16/2017 8:09:16 PM
Is Running: True
TIME_FORMAT = %m/%d/%Y %H:%M:%S %p
TIME_PREFIX = Started\sTime\:\s
MAX_TIMESTAMP_LOOKAHEAD = 20
Try this (every line has changed):
TIME_FORMAT = %m/%d/%Y %I:%M:%S %p
TIME_PREFIX = [\r\n]Started Time:\s*
MAX_TIMESTAMP_LOOKAHEAD = 22
Deploy to your Indexers and restart your Splunk instances there. Test by checking ONLY for events indexed AFTER the restarts.
Try this (every line has changed):
TIME_FORMAT = %m/%d/%Y %I:%M:%S %p
TIME_PREFIX = [\r\n]Started Time:\s*
MAX_TIMESTAMP_LOOKAHEAD = 22
Deploy to your Indexers and restart your Splunk instances there. Test by checking ONLY for events indexed AFTER the restarts.