2018-01-29 10:53 AM
In common parser, using the Log Parser Tool I can use the a time function to tell the parser how to exactly parse Date/Time data in the event. But I don't know if its possible to do so using a CEF parser....
My date format is: MM-DD-YYYY HH:MM:SS,mmm (01-25-2018 09:48:32,442) [24 hours format]
Any suggestions?
Regards,
Max
2018-01-31 09:40 AM
It seems that the CEF format only accept epoch time format as rt= field.
2018-01-31 09:40 AM
It seems that the CEF format only accept epoch time format as rt= field.