I have a csv tab-delimited file with entries that looks like this:
GPDB20A LTO3 L03 03/08/11 06:01:20 1299592880 03/08/11 08:09:46 1299600586
I want to grab the 4th field timestamp. With no TIME_PREFIX, it grabs the timestamp from the second field. When I use the TIME_PREFIX below, it uses the time that the event was indexed:
TIME_PREFIX = (?i)^(?:[^\t]*\t){3}
I got that regex from the field extractor in the GUI.
Any ideas, please?
Never mind - I found the answer here.
http://answers.splunk.com/questions/2062/how-can-i-extract-the-date-from-the-middle-of-an-event
Never mind - I found the answer here.
http://answers.splunk.com/questions/2062/how-can-i-extract-the-date-from-the-middle-of-an-event