Have data that Splunk is struggling with and needs props.conf and transforms.conf.
The year/month/date followed by time hours minutes seconds are in the 3rd and 4th fields for each event:
20170129|4928|20170128|191928|14390803651|DIMPLE|DESAITT|V123456|EMPLOYEE|058000-5440 SOMEDATA|05800001 SOMEDATA5440|3681-1-01 SOMEDATA|Open|GLOBAL|058000|3681|SOMEDATA|MUMBAI|INDIA|
20170129|4928|20170129|191928|14390803651|DIMPLE|DESAITT|E123456|EMPLOYEE|058000-5440 SOMEDATA|05800001 SOMEDATA5440|3681-1-01 SOMEDATA|Open|GLOBAL|058000|3681|SOMEDATA|CONGO|AFRICA|
Any help to sort time stamps and the pipe separated fields would be much appreciated.
↧