<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Collect's addtime=true/false : What does it do? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Collect-s-addtime-true-false-What-does-it-do/m-p/41927#M179019</link>
    <description>&lt;P&gt;I've got certain events that I want to send to collect.  I see the addtime option (defaults to true).  What does it do?&lt;/P&gt;

&lt;P&gt;My assumption was that setting it to false (addtime=f) uses the _time of the original event, but that doesn't seem to be the case.  No matter what I use, t or f, I get a timestamp of the current time when my search was piped to collect.  For example:&lt;/P&gt;

&lt;P&gt;mysearch for two files | diff | collect index=summary addtime=f&lt;/P&gt;

&lt;P&gt;(The search outputs just fine with the correct date when I append | addinfo to the end of the search above.)&lt;/P&gt;

&lt;P&gt;Splunk version 4.1.4.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Sep 2010 05:21:58 GMT</pubDate>
    <dc:creator>the_wolverine</dc:creator>
    <dc:date>2010-09-02T05:21:58Z</dc:date>
    <item>
      <title>Collect's addtime=true/false : What does it do?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Collect-s-addtime-true-false-What-does-it-do/m-p/41927#M179019</link>
      <description>&lt;P&gt;I've got certain events that I want to send to collect.  I see the addtime option (defaults to true).  What does it do?&lt;/P&gt;

&lt;P&gt;My assumption was that setting it to false (addtime=f) uses the _time of the original event, but that doesn't seem to be the case.  No matter what I use, t or f, I get a timestamp of the current time when my search was piped to collect.  For example:&lt;/P&gt;

&lt;P&gt;mysearch for two files | diff | collect index=summary addtime=f&lt;/P&gt;

&lt;P&gt;(The search outputs just fine with the correct date when I append | addinfo to the end of the search above.)&lt;/P&gt;

&lt;P&gt;Splunk version 4.1.4.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2010 05:21:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Collect-s-addtime-true-false-What-does-it-do/m-p/41927#M179019</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-09-02T05:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: Collect's addtime=true/false : What does it do?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Collect-s-addtime-true-false-What-does-it-do/m-p/41928#M179020</link>
      <description>&lt;P&gt;First of all, the option only has an effect if the results going into &lt;CODE&gt;collect&lt;/CODE&gt; do not have a &lt;CODE&gt;_raw&lt;/CODE&gt; field, i.e., usually output of (&lt;CODE&gt;si&lt;/CODE&gt;)&lt;CODE&gt;stats&lt;/CODE&gt; or (&lt;CODE&gt;si&lt;/CODE&gt;)&lt;CODE&gt;timechart&lt;/CODE&gt;. If you're using the &lt;CODE&gt;diff&lt;/CODE&gt; command, I expect you would have a &lt;CODE&gt;_raw&lt;/CODE&gt; field, so it doesn't do anything.&lt;/P&gt;

&lt;P&gt;In the case where there is no &lt;CODE&gt;_raw&lt;/CODE&gt; field, specifiying &lt;CODE&gt;addtime=f&lt;/CODE&gt; will have Splunk go through it's generic date detection against fields in whatever order they happen to be in the summary rows (usually lexicographic by field name). Using &lt;CODE&gt;addtime=t&lt;/CODE&gt; ensures that the search time range &lt;CODE&gt;info_min_time&lt;/CODE&gt; (which is added by &lt;CODE&gt;sistats&lt;/CODE&gt;) or &lt;CODE&gt;_time&lt;/CODE&gt; in the summary data gets used instead.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2010 05:52:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Collect-s-addtime-true-false-What-does-it-do/m-p/41928#M179020</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-09-02T05:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: Collect's addtime=true/false : What does it do?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Collect-s-addtime-true-false-What-does-it-do/m-p/41929#M179021</link>
      <description>&lt;P&gt;Thanks for the response.  Is there some other way to  inject my diff result into the index?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2010 06:52:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Collect-s-addtime-true-false-What-does-it-do/m-p/41929#M179021</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-09-02T06:52:46Z</dc:date>
    </item>
  </channel>
</rss>

