Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

If I have a custom sourcetype with fields delimited by commas, how do I extract the first field as the event timestamp?

$
0
0
If I have a custom sourcetype with fields delimited by `,`, the first field in the data is what I want to extract as the event time. What should be in the transforms.conf file for the FIELDS = ? The data looks like: `05-Oct-2016 12:45:17, Jon, Sally, Sue,` How should I configure transforms.conf? `FIELDS = ????, Name1, Name2, Name3`

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>