I have an autosys log with 4 columns (JobName|Start|End|Status) and would like to add them in splunk.
Two questions --
asked 30 May '12, 07:27
This link has an example that I included on your previous question. Splunk will only use one timestamp to represent the event time.
Once you get the regex ok for the TIME_PREFIX you will also need to set MAX_TIMESTAMP_LOOKAHEAD. In this case i think set it to 50.
answered 30 May '12, 07:46