Quantcast
Channel: Questions in topic: "props.conf"
Viewing all articles
Browse latest Browse all 1485

What is the best method of configuring timestamp recognition to support all ISO 8601 formats with Splunk 6.4.1

$
0
0
One of our teams wishes to use ISO 8601 for their log event timestamps. They have the desire to use any of the formats provided in that standard. Does Splunk 6.4.1 support timestamp recognition configuration for this? The logs currently use this variation: 2018-03-02T17:02:09.335Z What is the recommended way to configure timestamp recognition for the above sample?

Viewing all articles
Browse latest Browse all 1485

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>