I want to load a json into splunk. The time stamp of each event is in the format 2017-08-01T11:48:15.000+0000. I used %Y-%m-%dT%H:%M:%S.%3N+%z and similar combinations so that splunk recognises the time stamp but with no success. What is correct strptime format so that splunk understands this.
The %z
format variable includes the '+' so you don't have to specify it separately. Try %Y-%m-%dT%H:%M:%S.%3N%z
.
The %z
format variable includes the '+' so you don't have to specify it separately. Try %Y-%m-%dT%H:%M:%S.%3N%z
.
looks like it works fine:
try it:
| makeresults count=1
| eval t = "2017-08-01T11:48:15.000+0100, 2017-08-01T12:48:15.000+0200, 2017-08-01T13:48:15.000+0300"
| makemv delim="," t
| mvexpand t
| eval time = strptime(t, "%Y-%m-%dT%H:%M:%S.%3N%z")