Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do I configure Splunk to read events by timestamp?

$
0
0
Hello All our logging events start with a time stamp that looks like this: `00:00:23,746` The data in between the event can have carriage returns, along with different delimiters. For example data can contain `* ~ @ ^ | <>` …..etc. How can I get Splunk to read the events by timestamp? I don’t want any of the data between the time stamps to cause issues.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>