Skip to main content
Panther Knowledge Base

Can I use multiple timestamp formats in one schema in Panther?

QUESTION

My custom log schema uses a timestamp format of %Y-%m-%d %H:%M:%S.%f %z. Some log entries come in without the microsecond part (.%f). Is there a way to handle both timestamp formats (one with the .%f and one without) in the same schema file without having to treat it as simple string?

ANSWER

Panther does not currently support multiple timestamp formats in a single schema. 

 

  • Was this article helpful?