Videos

  • Add Videos
  • View All

Latest Activity

Profile IconWilliam S and Please... Dee Esssss :-) joined splunkninja
1 hour ago
Amine Recoba is now a member of splunkninja
yesterday
Michael Wilde replied to Nikita's discussion Count failures and success via transaction
"How are these transactions linked together... by a field called "ID"?  If so.. just build them with the field ID, and then use one of the MV commands to extract a field with success or failure in it.   Paste some samples and…"
Friday
Linus Myrefelt updated their profile
May 22
Marie updated their profile
May 21
Marie is now a member of splunkninja
May 21
Profile IconJitter and matthew arguin joined splunkninja
May 18
Profile IconMatthew Carter and Nikita joined splunkninja
May 17
Michael Wegener
  • Lees Summit, MO
  • United States
Share on Facebook Share on Facebook Share Twitter

Michael Wegener's Discussions

How to Configure timestamps for events with multiple timestamps
2 Replies

I followed the directions for configuring custom timestamps for events with multiple timestamps but I am not getting the result I am looking for. Here is my props.conf in my…Continue

Tags: configure, timestamps

Started this discussion. Last reply by Michael Wilde Jun 21, 2010.

 

Michael Wegener's Page

Gifts Received

Gift

Michael Wegener has not received any gifts yet

Give Michael Wegener a Gift

Latest Activity

Hagar replied to Michael Wegener's discussion How to Configure timestamps for events with multiple timestamps
"Try without the TIME_FORMAT leave only the TIME_PREFIX, my guess is that splunk will identified the format itself."
Jun 18, 2010
Michael Wegener posted a discussion

How to Configure timestamps for events with multiple timestamps

I followed the directions for configuring custom timestamps for events with multiple timestamps but I am not getting the result I am looking for. Here is my props.conf in my $Splunk_home$/etc/system/local/ folder: [host::foo.bar.com]TIME_PREFIX = \w+ \d+ \d\d:\d\d:\d\d foo.bar.com\s+TIME_FORMAT = %b %d %H:%M:%S %Y Here are a couple of entries that I am dealing with: Jun 14 08:18:20 foo.bar.com Mon Jun 14 08:16:25 2010: 123.123.123.12 -> 231.231.231.23: 43645 NOERR 'a.b.cdf.net.' AAAA IN…See More
Jun 14, 2010
Michael Wegener is now a member of splunkninja
Jun 14, 2010

Profile Information

Are you an existing splunk user?
Licensed
What do you do for your day job?
Learning to use Splunk

Comment Wall

  • No comments yet!

You need to be a member of splunkninja to add comments!

Join splunkninja

 
 
 

© 2012   Created by Michael Wilde.

Badges  |  Report an Issue  |  Terms of Service