Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

TIMESTAMP_FIELDS for different sources and timestamps using same sourcetype _json

$
0
0
Hello guys, TIMESTAMP_FIELDS must be setup in props.conf on indexers side, therefore how to use TIMESTAMP_FIELDS for different sources and timestamps using same sourcetype _json? Must we define sub-sourcetypes? Is it possible and how? First source : [_json] TIMESTAMP_FIELDS = @**timestamp** TIME_FORMAT = %Y-%m-%dT%H:%M:%S.%3N.%z Second source : [_json] TIMESTAMP_FIELDS = @**start** TIME_FORMAT = %Y-%m-%dT%H:%M:%S.%3N.%z Thanks.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>