Quantcast
Channel: Questions in topic: "props.conf"
Viewing all articles
Browse latest Browse all 1485

ADD_EXTRA_TIME_FIELDS=false leads to missing milliseconds

$
0
0
I have such props.conf [api] TZ = Europe/Moscow MAX_TIMESTAMP_LOOKAHEAD = 25 BREAK_ONLY_BEFORE = ^\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2},\d{3} BREAK_ONLY_BEFORE_DATE = true TIME_PREFIX = ^ MAX_EVENTS = 5000 CHARSET = AUTO KV_MODE = none NO_BINARY_CHECK = true category = Application description = CamelAPI TRANSFORMS-result = result And events like 2017-11-01 10:38:01,814 [20 ] ---------------------------- requestID=Server&1509521881805-1676215 messageID=MetroRequest@1509521881806-1029061 actor=Asop-> api=AsopApi method=asop_wr_start type=response elapsed=0.009 cardUID=04666B4AC34C80 cardNumber=0014175389 trxID=171100000226854667 trxPCID=72000DBDCC267407DB021DA042E4B268 session=136597463 And splunk recognize milliseconds until I add in my props.conf **ADD_EXTRA_TIME_FIELDS = false** After this every events apperars with time with zero milliseconds

Viewing all articles
Browse latest Browse all 1485

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>