<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Modification of _time value in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295922#M163729</link>
    <description>&lt;P&gt;While using the &lt;CODE&gt;collect&lt;/CODE&gt; command to change the timestamp, consider the discussion on this &lt;A href="https://answers.splunk.com/answers/608848/setting-the-timestamp-when-using-the-collect-comma.html"&gt;recent answers post&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;It doesn't seem as simple as setting a new &lt;CODE&gt;_time&lt;/CODE&gt; value before piping to &lt;CODE&gt;collect&lt;/CODE&gt;.&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jan 2018 21:15:50 GMT</pubDate>
    <dc:creator>micahkemp</dc:creator>
    <dc:date>2018-01-11T21:15:50Z</dc:date>
    <item>
      <title>Modification of _time value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295913#M163720</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;When I create a new index with an old index I would like to have an _time with a time different than the time of the day that I create my index.&lt;/P&gt;

&lt;P&gt;Is it possible ?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 17:16:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295913#M163720</guid>
      <dc:creator>isabellechristo</dc:creator>
      <dc:date>2018-01-11T17:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: Modification of _time value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295914#M163721</link>
      <description>&lt;P&gt;Can you rephrase the question?  It's unclear (at least to me) what it is you're asking.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 20:08:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295914#M163721</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2018-01-11T20:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: Modification of _time value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295915#M163722</link>
      <description>&lt;P&gt;By exemple :&lt;/P&gt;

&lt;P&gt;Index1 : _raw with _time 01/01/2017 &lt;/P&gt;

&lt;P&gt;index2 is creating on 01/01/2018 and I would like to have in _raw  01/01/2017 for _time &lt;/P&gt;

&lt;P&gt;it is for having in presets a value of research that I can have for the data in the initial index.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 20:17:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295915#M163722</guid>
      <dc:creator>isabellechristo</dc:creator>
      <dc:date>2018-01-11T20:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: Modification of _time value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295916#M163723</link>
      <description>&lt;P&gt;Timestamps aren't a function of the index, they are a function of the sourcetype.&lt;/P&gt;

&lt;P&gt;Do you want to index different event formats with different time formats?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 20:21:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295916#M163723</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2018-01-11T20:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: Modification of _time value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295917#M163724</link>
      <description>&lt;P&gt;Are you ingesting (or planning to ingest) same data in both the index? If yes, from where are you getting this data? OR you've data in Index1 and just want to replicate same data but adjusted timestmap in Index2?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 20:33:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295917#M163724</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-01-11T20:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: Modification of _time value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295918#M163725</link>
      <description>&lt;P&gt;I would like to replicate same data but adjusted timestamp in index2&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 20:36:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295918#M163725</guid>
      <dc:creator>isabellechristo</dc:creator>
      <dc:date>2018-01-11T20:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: Modification of _time value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295919#M163726</link>
      <description>&lt;P&gt;I would like to adjust the timestamp in the new index &lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 20:41:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295919#M163726</guid>
      <dc:creator>isabellechristo</dc:creator>
      <dc:date>2018-01-11T20:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: Modification of _time value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295920#M163727</link>
      <description>&lt;P&gt;You can use summary indexing method (collect command or by scheduling a search and enabling summary indexing) to send your Index1 data to Index2. In your search, you'd manipulate your _time before sending (adding 1 year). A sample search (using collect command) could be like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=Index1 sourcetype=yoursourcetype
| eval _time=relative_time(_time,"+1y")
| collect index=Index2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;See more info on collect command here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.1/SearchReference/Collect"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.1/SearchReference/Collect&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 20:46:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295920#M163727</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-01-11T20:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: Modification of _time value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295921#M163728</link>
      <description>&lt;P&gt;and if I want to put in _time an other value than _time like by example in _time I would to put a date witch is not _time . Is it possible ?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 21:03:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295921#M163728</guid>
      <dc:creator>isabellechristo</dc:creator>
      <dc:date>2018-01-11T21:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: Modification of _time value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295922#M163729</link>
      <description>&lt;P&gt;While using the &lt;CODE&gt;collect&lt;/CODE&gt; command to change the timestamp, consider the discussion on this &lt;A href="https://answers.splunk.com/answers/608848/setting-the-timestamp-when-using-the-collect-comma.html"&gt;recent answers post&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;It doesn't seem as simple as setting a new &lt;CODE&gt;_time&lt;/CODE&gt; value before piping to &lt;CODE&gt;collect&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 21:15:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295922#M163729</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2018-01-11T21:15:50Z</dc:date>
    </item>
    <item>
      <title>Re: Modification of _time value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295923#M163730</link>
      <description>&lt;P&gt;You should be able to manipulate _time within the compound of eval command and available values/function in your Splunk. If you can describe what kind of changes exactly you're planning to make, we can have a look at it's feasibility.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 21:30:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Modification-of-time-value/m-p/295923#M163730</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-01-11T21:30:43Z</dc:date>
    </item>
  </channel>
</rss>

