Hello All,
Please help us parse the endTimeISO, startTimeISO and eventTimeISO from the below log.
"{\\"hostName\\":\\"ManageEngine Endpoint Central 11\\",\\"module\\":\\"System Manager\\",\\"priority\\":\\"Information\\",\\"timeDuration\\":\\"0\\",\\"application\\":\\"ManageEngine Endpoint Central 11\\",\\"computerName\\":\\"***-***\\",\\"domainName\\":\\"****\\",\\"viewerIp\\":\\"--\\",\\"eventTime\\":\\"1703582047178\\",\\"userIp\\":\\"--\\",\\"startTime\\":\\"1703582047178\\",\\"endTime\\":\\"1703582047178\\",\\"remarks\\":\\"****-****-***\\",\\"userName\\":\\"--\\",\\"startTimeISO\\":\\"2023-12-26T14:44:07.178+05:30\\",\\"endTimeISO\\":\\"2023-12-26T14:44:07.178+05:30\\",\\"eventTimeISO\\":\\"2023-12-26T14:44:07.178+05:30\\"}
Solved
How can I parse Timestamp?
Best answer by lukas-lr
Hi,
The above format is working, but we couldn't find the field date getting parsed. The date value is not getting mapped in the statedump.

Can you please let us know how to parse as event time?
Hi, the date filter should automatically set the "@timestamp" field, which is then used as the log timestamp in Chronicle
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.

