<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Difference between (_time) internal field and (timestamp) default field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445339#M126326</link>
    <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/Aboutdefaultfields"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/Aboutdefaultfields&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Feb 2019 17:51:40 GMT</pubDate>
    <dc:creator>PowerPacked</dc:creator>
    <dc:date>2019-02-05T17:51:40Z</dc:date>
    <item>
      <title>Difference between (_time) internal field and (timestamp) default field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445335#M126322</link>
      <description>&lt;P&gt;Guys&lt;/P&gt;

&lt;P&gt;I cant find the difference between _time internal field and timestamp default field in docs anywhere, Can someone help me with this &lt;BR /&gt;
or are they same ?&lt;/P&gt;

&lt;P&gt;Here is the link to Splunk doc which shows them differently.&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/Aboutdefaultfields"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/Aboutdefaultfields&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2019 06:47:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445335#M126322</guid>
      <dc:creator>PowerPacked</dc:creator>
      <dc:date>2019-02-05T06:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between (_time) internal field and (timestamp) default field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445336#M126323</link>
      <description>&lt;P&gt;There is no "timestamp" default field. Are you able to supply more information about where you are seeing this field?   It might be an indexed extraction or appearing because of some other reason.&lt;/P&gt;

&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2019 06:50:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445336#M126323</guid>
      <dc:creator>chrisyounger</dc:creator>
      <dc:date>2019-02-05T06:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between (_time) internal field and (timestamp) default field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445337#M126324</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93566"&gt;@PowerPacked&lt;/a&gt; &lt;/P&gt;

&lt;P&gt;I guess you are talking about TIMESTAMP_FIELDS parameter in props.conf.&lt;BR /&gt;
First of all TIMESTAMP_FIELD is a field in your data which will at the end contribute to _time. Like if you have some structured data where you have multiple time fields so you can specify which field should be _time. So we mention the TIMESTAMP field there.&lt;/P&gt;

&lt;P&gt;For better understanding, refer this link: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/Admin/Propsconf
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I hope this answers your question.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:09:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445337#M126324</guid>
      <dc:creator>vishaltaneja070</dc:creator>
      <dc:date>2020-09-29T23:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between (_time) internal field and (timestamp) default field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445338#M126325</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/Aboutdefaultfields"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/Aboutdefaultfields&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2019 17:51:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445338#M126325</guid>
      <dc:creator>PowerPacked</dc:creator>
      <dc:date>2019-02-05T17:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between (_time) internal field and (timestamp) default field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445339#M126326</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/Aboutdefaultfields"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/Aboutdefaultfields&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2019 17:51:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445339#M126326</guid>
      <dc:creator>PowerPacked</dc:creator>
      <dc:date>2019-02-05T17:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between (_time) internal field and (timestamp) default field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445340#M126327</link>
      <description>&lt;P&gt;Yes they are indexed extractions default fields - but i would like to know diff between them&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2019 17:53:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445340#M126327</guid>
      <dc:creator>PowerPacked</dc:creator>
      <dc:date>2019-02-05T17:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between (_time) internal field and (timestamp) default field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445341#M126328</link>
      <description>&lt;P&gt;_time is the time of the event in epoch time.&lt;/P&gt;

&lt;P&gt;the other fields such as &lt;CODE&gt;date_hour&lt;/CODE&gt; and &lt;CODE&gt;date_minute&lt;/CODE&gt; etc are just partial versions there to be helpful. For example, if you wanted to find out the most poular hour of the day in your data you can do this: &lt;CODE&gt;SEARCH | stats count by date_hour&lt;/CODE&gt; . Now if you dont like these fields you can disable them by setting this  in props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ADD_EXTRA_TIME_FIELDS = [true|false]
* This setting controls whether or not the following keys will be automatically
  generated and indexed with events:
    date_hour, date_mday, date_minute, date_month, date_second, date_wday,
    date_year, date_zone, timestartpos, timeendpos, timestamp.
* These fields are never required, and may be turned off as desired.
* Defaults to true and is enabled for most data sources.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 05 Feb 2019 19:01:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445341#M126328</guid>
      <dc:creator>chrisyounger</dc:creator>
      <dc:date>2019-02-05T19:01:15Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between (_time) internal field and (timestamp) default field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445342#M126329</link>
      <description>&lt;P&gt;The timestamp that is presented to you is the &lt;CODE&gt;_time&lt;/CODE&gt; value adjusted by your personal &lt;CODE&gt;Time zone&lt;/CODE&gt; setting in you &lt;CODE&gt;user&lt;/CODE&gt; settings.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2019 19:50:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445342#M126329</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-02-05T19:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between (_time) internal field and (timestamp) default field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445343#M126330</link>
      <description>&lt;P&gt;Thanks for the answer&lt;/P&gt;

&lt;P&gt;If you go through the above doc in the question, it says&lt;/P&gt;

&lt;P&gt;Splunk will extract default fields like host,timestamp,source etc. &amp;amp; Internal fields like _time,_raw, etc. for every event at index time&lt;/P&gt;

&lt;P&gt;I can see _time, linecount,punct all other internal &amp;amp; default field value for every event&lt;BR /&gt;
but i dont see timestamp field value for any event.&lt;/P&gt;

&lt;P&gt;&amp;amp; i am trying to understand diff between _time and timestamp field value for any event.&lt;/P&gt;

&lt;P&gt;Can you explain me this or provide sample image which shows _time and timestamp field value for any event.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:05:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Difference-between-time-internal-field-and-timestamp-default/m-p/445343#M126330</guid>
      <dc:creator>PowerPacked</dc:creator>
      <dc:date>2020-09-29T23:05:26Z</dc:date>
    </item>
  </channel>
</rss>

