<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using index time as time stamp in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Using-index-time-as-time-stamp/m-p/51462#M9875</link>
    <description>&lt;P&gt;Is there anyway to ignore the events time stamp, and set it to the current system time (at the event's index time)?&lt;/P&gt;

&lt;P&gt;I'm using light weight forwarders so I assume this would need to be done on the indexer.  &lt;/P&gt;</description>
    <pubDate>Tue, 01 Mar 2011 03:06:58 GMT</pubDate>
    <dc:creator>carmackd</dc:creator>
    <dc:date>2011-03-01T03:06:58Z</dc:date>
    <item>
      <title>Using index time as time stamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-index-time-as-time-stamp/m-p/51462#M9875</link>
      <description>&lt;P&gt;Is there anyway to ignore the events time stamp, and set it to the current system time (at the event's index time)?&lt;/P&gt;

&lt;P&gt;I'm using light weight forwarders so I assume this would need to be done on the indexer.  &lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2011 03:06:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-index-time-as-time-stamp/m-p/51462#M9875</guid>
      <dc:creator>carmackd</dc:creator>
      <dc:date>2011-03-01T03:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Using index time as time stamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-index-time-as-time-stamp/m-p/51463#M9876</link>
      <description>&lt;P&gt;I was looking through the documentation and found the answer shortly after I posted.&lt;/P&gt;

&lt;P&gt;If your events are indexed in real time, increase Splunk's overall indexing performance by turning off timestamp lookahead (set MAX_TIMESTAMP_LOOKAHEAD = 0). This causes Splunk to not look into event's for a timestamp, and sets an event's timestamp to be its indexing time (using current system time).  &lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2011 03:12:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-index-time-as-time-stamp/m-p/51463#M9876</guid>
      <dc:creator>carmackd</dc:creator>
      <dc:date>2011-03-01T03:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: Using index time as time stamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-index-time-as-time-stamp/m-p/51464#M9877</link>
      <description>&lt;P&gt;You should be able to do this using props.conf on the indexer (since you're using LWF)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[mysourcetype]
DATETIME_CONFIG = CURRENT
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;See &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Propsconf" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/Admin/Propsconf&lt;/A&gt; for more info.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2011 03:14:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-index-time-as-time-stamp/m-p/51464#M9877</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2011-03-01T03:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: Using index time as time stamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-index-time-as-time-stamp/m-p/51465#M9878</link>
      <description>&lt;P&gt;Thanks, this worked, but MAX_TIMESTAMP_LOOKAHEAD = 0 did not, which confuses me. Why would the documentation say setting the MAX_TIMESTAMP_LOOKAHEAD to 0 will cause splunk not to look into the event for a timestamp, and use the the current system time as the timestamp? I did not see this behavior when I used this configuration.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:25:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-index-time-as-time-stamp/m-p/51465#M9878</guid>
      <dc:creator>carmackd</dc:creator>
      <dc:date>2020-09-28T09:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: Using index time as time stamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-index-time-as-time-stamp/m-p/51466#M9879</link>
      <description>&lt;P&gt;Can you post a link to where you found that in the docs?  I didn't see it in the reference for props.conf, which confused me a little.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2011 23:31:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-index-time-as-time-stamp/m-p/51466#M9879</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2011-03-01T23:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: Using index time as time stamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-index-time-as-time-stamp/m-p/51467#M9880</link>
      <description>&lt;P&gt;Docs scrubbed.  Sorry, old error.  Passes smell test but was incorrect.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2011 05:09:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-index-time-as-time-stamp/m-p/51467#M9880</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2011-03-02T05:09:49Z</dc:date>
    </item>
  </channel>
</rss>

