Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

YYYYMM timestamp - can Splunk extract time using strptime?

$
0
0
My data format can be seen below (CSV). The date field ("PERIOD") is in %Y%m format. ...,PERIOD ...,201512 Although the following props.conf does not work: [ csv ] CHARSET=UTF-8 INDEXED_EXTRACTIONS=csv KV_MODE=none SHOULD_LINEMERGE=false category=Structured TIME_FORMAT=%Y%m TIMESTAMP_FIELDS=PERIOD Any ideas what I'm doing wrong guys?

Viewing all articles
Browse latest Browse all 47296

Trending Articles