Quantcast
Channel: Questions in topic: "props.conf"
Viewing all articles
Browse latest Browse all 1485

How do I edit my props.conf for proper timestamp extraction from my sample log entry?

$
0
0
I'm having trouble with a log and getting Splunk to recognize the time format. Here is an example a log entry: 010406:00:530000000000000040RD000001071215 Now, all the entries start with `0104` followed by the time in `H:M:S` format. I've added a props.conf to the indexer like this: [sisfeedlog] TIME_PREFIX = ^0104 TIME_FORMAT = %H:%M:%S MAX_TIMESTAMP_LOOKAHEAD = 8 and a props.conf on the server: [source::...\\SISFeed\\S(\d+\.LOG)] sourcetype = sisfeedlog It doesn't seem to be working though as the time isn't being extracted and the sourcetype is coming up as unknown. Any advise on why it's not working? Thanks, Mark

Viewing all articles
Browse latest Browse all 1485

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>