By default, when Sumo parses logs, it sets the message timestamps by automatically parsing log entries. I see only the first timestamp in a log entry is converted. My logs have more than one timestamp entry per message, in the following format: "2014-08-01 09:15:38.520 -0700".
Since the format is recognized and automatically converted, how can all timestamps in a message be converted like the first?
I failed with manual attempts, like below, but I'm not familiar with the correct syntax.
| parse field=end_time "yyyy-MM-dd HH:mm:ss.SSS ZZZZ" as end_time_mod
Please sign in to leave a comment.