<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log Analytics Timestamp in Splunk AppDynamics</title>
    <link>https://community.splunk.com/t5/Splunk-AppDynamics/Log-Analytics-Timestamp/m-p/718081#M804</link>
    <description>&lt;P&gt;Hi All!&lt;/P&gt;
&lt;P&gt;We are using the syslog functionality of the analytics agent to collect data.&lt;/P&gt;
&lt;P&gt;The logs may be from the past so the creation timestamp is also in the past.&lt;/P&gt;

&lt;P&gt;My problem is that AppD always considers the ingestion date as the "timestamp". We can extract the timestamp from the message with regexp but we are not able to use it for charting.&lt;/P&gt;
&lt;P&gt;So when we bulk load logs into AppD we try charting we can use only the "ingestion" timestamp so the chart/widget won't be accurate at all.&lt;/P&gt;

&lt;P&gt;Do you know who to work around this? We want to use customer timestamps so that we can create accurate charting.&lt;/P&gt;

&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Sandor&lt;/P&gt;</description>
    <pubDate>Mon, 23 Dec 2019 14:20:19 GMT</pubDate>
    <dc:creator>Sandor_Bihary</dc:creator>
    <dc:date>2019-12-23T14:20:19Z</dc:date>
    <item>
      <title>Log Analytics Timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-AppDynamics/Log-Analytics-Timestamp/m-p/718081#M804</link>
      <description>&lt;P&gt;Hi All!&lt;/P&gt;
&lt;P&gt;We are using the syslog functionality of the analytics agent to collect data.&lt;/P&gt;
&lt;P&gt;The logs may be from the past so the creation timestamp is also in the past.&lt;/P&gt;

&lt;P&gt;My problem is that AppD always considers the ingestion date as the "timestamp". We can extract the timestamp from the message with regexp but we are not able to use it for charting.&lt;/P&gt;
&lt;P&gt;So when we bulk load logs into AppD we try charting we can use only the "ingestion" timestamp so the chart/widget won't be accurate at all.&lt;/P&gt;

&lt;P&gt;Do you know who to work around this? We want to use customer timestamps so that we can create accurate charting.&lt;/P&gt;

&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Sandor&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2019 14:20:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-AppDynamics/Log-Analytics-Timestamp/m-p/718081#M804</guid>
      <dc:creator>Sandor_Bihary</dc:creator>
      <dc:date>2019-12-23T14:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: Log Analytics Timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-AppDynamics/Log-Analytics-Timestamp/m-p/718082#M805</link>
      <description>&lt;P&gt;Hi All!&lt;/P&gt;&lt;P&gt;I just re-up this thread.&lt;/P&gt;&lt;P&gt;Does anyone know how to alter the timestamp when we feed in data into the log analytics?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2020 06:43:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-AppDynamics/Log-Analytics-Timestamp/m-p/718082#M805</guid>
      <dc:creator>Sandor_Bihary</dc:creator>
      <dc:date>2020-01-13T06:43:22Z</dc:date>
    </item>
  </channel>
</rss>

