Getting Data In

Handy timestamp format extraction tool

rturk
Builder

Hi Splunkers!

This is less of a question, and more of a (hopefully) handy tip that I hope will answer peoples questions when they go looking for an answer to timestamp extraction issues, specifically when setting TIMESTAMP_FORMAT in props.conf.

If you're looking to get a timestamp in strptime/strftime format, I've found this site really useful:

http://www.strftime.net/

It's not owned/run by me, and as far as I can tell has no ads.

Hope it helps!

RT 🙂

0 Karma
1 Solution

rturk
Builder

Like I said, this is just to hopefully help people out - so I'll answer my own question 🙂

View solution in original post

0 Karma

rturk
Builder

Like I said, this is just to hopefully help people out - so I'll answer my own question 🙂

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...