Getting Data In

Time format throwing error

saifuddin9122
Path Finder

Hello All,

i have a sourcetype with timestamp as "2017-10-10T18:55:47.425Z" and i defined TIME_FORMAT as "%Y-%m-%dT%H:%M:%S.%3%Z" but seems to be issue am getting the following error

Bad strptime format value: '%Y-%m-%dT%H:%M:%S.%3%Z', of param: props.conf / [] / TIME_FORMAT.

can anyone help me in correcting it?

0 Karma
1 Solution

s2_splunk
Splunk Employee
Splunk Employee

Try with TIME_FORMAT as "%Y-%m-%dT%H:%M:%S.%3N%Z"

View solution in original post

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Try with TIME_FORMAT as "%Y-%m-%dT%H:%M:%S.%3N%Z"

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...