Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

sysmon props.conf _time extractions is working but isn't adding the milliseconds that it should from the UTCTime value.

$
0
0
My props.conf time extraction looks like this and works great for extracting the time and milliseconds from the tool to get data in in splunk. Added it for both Xml source and WinEventLog. [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational] SHOULD_LINEMERGE=false NO_BINARY_CHECK=true BREAK_ONLY_BEFORE= MAX_TIMESTAMP_LOOKAHEAD=23 TIME_FORMAT=%Y-%m-%d %H:%M:%S.%3Q [WinEventLog://Microsoft-Windows-Sysmon/Operational] SHOULD_LINEMERGE=false NO_BINARY_CHECK=true BREAK_ONLY_BEFORE= MAX_TIMESTAMP_LOOKAHEAD=23 TIME_FORMAT=%Y-%m-%d %H:%M:%S.%3Q ![alt text][1] [1]: /storage/temp/254786-sysmon.jpg

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>