Hello All,
Please help us parse the endTimeISO, startTimeISO and eventTimeISO from the below log.
"{\"hostName\":\"ManageEngine Endpoint Central 11\",\"module\":\"System Manager\",\"priority\":\"Information\",\"timeDuration\":\"0\",\"application\":\"ManageEngine Endpoint Central 11\",\"computerName\":\"***-***\",\"domainName\":\"****\",\"viewerIp\":\"--\",\"eventTime\":\"1703582047178\",\"userIp\":\"--\",\"startTime\":\"1703582047178\",\"endTime\":\"1703582047178\",\"remarks\":\"****-****-***\",\"userName\":\"--\",\"startTimeISO\":\"2023-12-26T14:44:07.178+05:30\",\"endTimeISO\":\"2023-12-26T14:44:07.178+05:30\",\"eventTimeISO\":\"2023-12-26T14:44:07.178+05:30\"}
Solved! Go to Solution.
Hi, the date filter should automatically set the "@timestamp" field, which is then used as the log timestamp in Chronicle