Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to configure the HTTP Event Collector to use 6 digits of precision in the epoch time field?

$
0
0
We are trying to get input time with 6 digits of precision but Splunk seems to only accept 5. We are using the HTTP Event Collector to input data into Splunk. As described in the documentation, we input the time in epoch time format: "*The default time format is epoch time format, in the format .. For example, 1433188255.500 indicates 1433188255 seconds and 500 milliseconds after epoch, or Monday, June 1, 2015, at 7:50:55 PM GMT.*" Although this suggests that the maximum precision of the time field could be 3 digits, in practice we've found it actually to be 5 digits. However, we actually need the time to have 6 digits of precision. Is there any way to make that happen? Other posts on here have suggested that internally Splunk can store up to 6 digits of precision, but when sending 6 digits to Splunk through the HTTP Event Collector, the last digit seems to be dropped. Any help would be greatly appreciated!

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>