Interesting note , I used 3 methods to get characters and deal with several lines in my data:
| abstract maxterms=24 maxlines=1
-I wanted to only see the first line but this pulled 24 characters into one line. Not too bad though.
| rex "^(?.{24})"
-Did not match the new line, returned nothing if first line was shorter than 24 characters.
| eval TIME=substr(_raw,1,24)
-Going to use this one.
Using this to look at TIME_PREFIX, MAX_TIMESTAMP_LOOKAHEAD, and TIME_FORMAT settings in bulk.
... View more