Getting Data In

Time stamp configuration in props.conf

aalhabbash1
Path Finder

Hi Splunker;

How can set (TIME_PREFIX, TIME_FORMAT, and MAX_TIMESTAMP_LOOKAHEAD) in props.conf if there change of timestamp location in each events?

you can see the sample logs in the attachment about my different time stamp event, show different locations for each event, how can set that?

][1]

Please help me in that.

BR;

Tags (1)
0 Karma
1 Solution

rmjharris
Path Finder

The examples you posted look like you could trust Splunk to find the timestamps automatically. However, if you want to do it manually then you are going to need to create a xml file with the various timestamps and reference it in props.conf.

[mysourcetype]
DATETIME_CONFIG = /etc/system/local/custom_datetime.xml

Documentation

View solution in original post

rmjharris
Path Finder

The examples you posted look like you could trust Splunk to find the timestamps automatically. However, if you want to do it manually then you are going to need to create a xml file with the various timestamps and reference it in props.conf.

[mysourcetype]
DATETIME_CONFIG = /etc/system/local/custom_datetime.xml

Documentation

Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...