Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Index native_stdout.log with no dates but only time-stamps

$
0
0
Trying to index a native_stdout.log that has no dates in the first line and only has time-stamps. 07:26:49,602 INFO [ServerImpl] 07:26:49,602 INFO [ServerImpl] 07:26:49,602 INFO [ServerImpl] 07:26:49,602 INFO [ServerImpl] 07:26:49,602 INFO [ServerImpl] Splunk indexed the file by using the file modified date. Is this the expected behavior when the log file has no dates?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>