Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

timestamp=none

$
0
0
I acquired some logs from a scrip (close to ps.sh) with a timestamp correctly recognized at index time. The problem is that the "timestamp" field is always equal to "none" so I cannot have the other date fields (date_wday, date_hour, etc...). I tried to configure the TIMESTAMP_FORMAT but I always acquire events with "timestamp=none". Anyone has any idea? thank you in advance. Bye. Giuseppe

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>