Splunk Props is not considering AM PM. Need to consider AM PM value and convert the time into 24 hour time format for the below sample log.
Log Sample:
5465465||TEXT||546546545445|65465|TEXT|TEXT|TEXT|TEXT|||0||TEXT||TEXT||||||||TEXT||13-JAN-20 06.09.59.000000 PM|||||||||||||||
Existing Props configuration:
DATETIME_CONFIG =
FIELD_DELIMITER = |
INDEXED_EXTRACTIONS = csv
KV_MODE = none
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = false
TIMESTAMP_FIELDS = "Field name where time is exist with am/pm"
category = Structured
disabled = false
pulldown_type = true
Try telling Splunk what the timestamp field looks like.
TIME_FORMAT = %d-%b-%y %I.%M.%S.%6N %p
Try telling Splunk what the timestamp field looks like.
TIME_FORMAT = %d-%b-%y %I.%M.%S.%6N %p