My props.conf time extraction looks like this and works great for extracting the time and milliseconds from the tool to get data in in splunk.
Added it for both Xml source and WinEventLog.
[XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
SHOULD_LINEMERGE=false
NO_BINARY_CHECK=true
BREAK_ONLY_BEFORE=
MAX_TIMESTAMP_LOOKAHEAD=23
TIME_FORMAT=%Y-%m-%d %H:%M:%S.%3Q
[WinEventLog://Microsoft-Windows-Sysmon/Operational]
SHOULD_LINEMERGE=false
NO_BINARY_CHECK=true
BREAK_ONLY_BEFORE=
MAX_TIMESTAMP_LOOKAHEAD=23
TIME_FORMAT=%Y-%m-%d %H:%M:%S.%3Q
![alt text][1]
[1]: /storage/temp/254786-sysmon.jpg
↧