|
Hi, How do I get splunk to show the date and time correctly based on the event?For example if I have the following event from oracle logs: RETURNCODE=0,OS_PROCESS=1671350,EXTENDED_TIMESTAMP="22/07/10 12:55:50.251291 PM +08:00",TO_CHAR(EXTENDED_TIMESTAMP,'MM="07/22/2010 12:55:50",OS_USERNAME=,USERNAME=,USERHOST=,OBJ_NAME=,SCN=,ACTION=,TRANSACTIONID=,ACTION_NAME="" Splunk is displaying the incorrect date as: Some events may translate with incorrect time as well. Have tried using "DATETIME config=current" in props.conf,but still there is a time differences as the splunk and oracle server time is not in sync. Any idea? |
|
remy you can try something like this: [source::e:\logs\yourlogs\*] Here are the docs on this, read them for more knowledge on how to deal with this: Configure Timestamp Recognition Cheers, |