Getting Data In

Datetime.xml - extracting hour that does not exist

twkan
Splunk Employee
Splunk Employee

Hello all,

I have a series of logs that looks like this:

200312,111523  -> this means 20 March 2012, 11:15:23 am
200312,53344  -> this means 20 March 2012, 05:33:44 am (note that the first 0 is missing in the hour)
200312,1428 -> this means 20 March 2012, 00:14:28 am (note that the first two 00 are missing in the hour)

I have already written the datetime.xml to cater for the first two scenarios. But for the 3rd one where the hour is totally missing, how do I cater for this on my datetime.xml?

Has anyone managed to think of a way to 'substitue' 00 as the hour if it's missing from the logs itself?

Thanks for any insights.

0 Karma
1 Solution

twkan
Splunk Employee
Splunk Employee

Okay, decided to write a script to pad the time with zeros before being indexed by Splunk.

View solution in original post

0 Karma

twkan
Splunk Employee
Splunk Employee

Okay, decided to write a script to pad the time with zeros before being indexed by Splunk.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...