Quantcast
Channel: Questions in topic: "props.conf"
Viewing all articles
Browse latest Browse all 1485

How to edit my TIME_PREFIX in props.conf to properly extract the timestamp from my sample event?

$
0
0
-health_checkin_date: 2016-10-30T09:45:28.824Z That is the line from a JSON event being sent into my Splunk instance via TCP syslog. It's being put into an index in an app I made, so I added the following the props.conf of that app: [company_product] TRUNCATE=0 TIME_PREFIX=\"-health_checkin_date\":\s TIME_FORMAT=%Y-%m-%dT%T.%3N%Z CHARSET=AUTO KV_MODE=NONE INDEXED_EXTRACTIONS=JSON This stanza matches what is set in the TCP receiver as the custom sourcetype for this port, but the timestamp isn't being properly extracted. I'm intentionally prefixing the field with a hyphen so Splunk will find it quickly in the event. Am I editing the wrong props.conf?

Viewing all articles
Browse latest Browse all 1485

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>