A little bit strange as this time stamp is not being recognized -
This is because you did not set your base configs in props.conf
and Splunk is guessing at your time format.
You should add this to your indexer(s), restart the Splunkd service and it will work properly.
[sourcetype]
TIME_PREFIX = ^
TIME_FORMAT = %Y-%m-%d %H:%M:%S.%3n
This is because you did not set your base configs in props.conf
and Splunk is guessing at your time format.
You should add this to your indexer(s), restart the Splunkd service and it will work properly.
[sourcetype]
TIME_PREFIX = ^
TIME_FORMAT = %Y-%m-%d %H:%M:%S.%3n
Great @skoelpin. So which format(s) is being detected without configurations?
What does your props.conf look like? Particularly TIME_FORMAT ?
nothing for now ; -)