Hello,
I have events without a timestamp like epochtime or a format like 2020-02-03 18:41:00.
The needed information is kind of split up in the raw event. Raw events look like this sample:
sometext, date,20200203, some text, some text, time,184100, some text
Is it possible to create a useful timestamp extraction of out this during the data onboarding?
Best regards
you have to use custom datetime config which allows regexes between date and time:
https://www.function1.com/2013/01/oh-no-splunking-log-files-with-multiple-formats-no-problem
Are these coming from the same source or from different sources heading to the same index?
if I understand it correctly the date and the time are in the same log event, which implies it comes from the same source
Okay then you need to figure out which format the date and timestamp mark the beginning of a new event. Then you can create custom event breakers for that specific data source.
Figure out which time stamp is shown in EVERY event that marks the beginning of that event, and I can help you with the rest.
you have to use custom datetime config which allows regexes between date and time:
https://www.function1.com/2013/01/oh-no-splunking-log-files-with-multiple-formats-no-problem