Refine your search:

I have an example log file with the following format:

Nov 05 10:33:37 servername applicationserver: instance,ipaddress,[05/Nov/2011:10:33:33 +0000]

I would like the second time column which contains [05/Nov/2011:10:33:33 +0000] to be column which is used for _time at index time, currently by default it uses Nov 05 10:33:37.

Any suggestion on how to tech splunk to use the alternative timestamp for _time would be appreciated.

Thanks

asked 15 Nov '11, 08:10

camah4's gravatar image

camah4
11
accept rate: 0%

closed 15 Nov '11, 09:35

araitz's gravatar image

araitz ♦
7.9k3925

Please create only one post per question:

http://splunk-base.splunk.com/answers/34422/default-_time

(15 Nov '11, 09:36) araitz ♦

The question has been closed for the following reason "Duplicate Content" by araitz 15 Nov '11, 09:35


One Answer:
link

answered 15 Nov '11, 08:40

Takajian's gravatar image

Takajian
7452315
accept rate: 18%

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×28

Asked: 15 Nov '11, 08:10

Seen: 350 times

Last updated: 15 Nov '11, 09:36

Copyright © 2005-2012 Splunk Inc. All rights reserved.