<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: logstash overwrite _time field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-consider-quot-time-quot-as-quot-time-quot-on/m-p/646931#M223916</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;There are ways to do it. I point to another answers where it has solved:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/HEC-timestamp-recognition/m-p/537762" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/HEC-timestamp-recognition/m-p/537762&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/JSON-timestamps-not-parsed-via-HTTP-Event-Collector/m-p/204689" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/JSON-timestamps-not-parsed-via-HTTP-Event-Collector/m-p/204689&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Http-Event-Collector-ignores-JSON-timestamp/m-p/497681" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Http-Event-Collector-ignores-JSON-timestamp/m-p/497681&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/HEC-How-to-set-time-on-base-of-a-specific-JSON-field/m-p/515486" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/HEC-How-to-set-time-on-base-of-a-specific-JSON-field/m-p/515486&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;There are several other post covering this. Main point is use raw endpoint or set time field on json's "header" part outside of actual payload.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jun 2023 08:21:33 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2023-06-14T08:21:33Z</dc:date>
    <item>
      <title>Is it possible to consider "time" as "_time" on logstash config?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-consider-quot-time-quot-as-quot-time-quot-on/m-p/646929#M223914</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I have logstash config that send logs to Splunk HEC.&lt;/P&gt;
&lt;P&gt;these data contain field that call "time".&lt;/P&gt;
&lt;P&gt;Now question is: Is it possible to consider "time" as "_time" on logstash config?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FYI: i want to consider this time as _time not the time that splunk receive it&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 23:08:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-consider-quot-time-quot-as-quot-time-quot-on/m-p/646929#M223914</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2023-06-15T23:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: logstash overwrite _time field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-consider-quot-time-quot-as-quot-time-quot-on/m-p/646931#M223916</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;There are ways to do it. I point to another answers where it has solved:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/HEC-timestamp-recognition/m-p/537762" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/HEC-timestamp-recognition/m-p/537762&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/JSON-timestamps-not-parsed-via-HTTP-Event-Collector/m-p/204689" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/JSON-timestamps-not-parsed-via-HTTP-Event-Collector/m-p/204689&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Http-Event-Collector-ignores-JSON-timestamp/m-p/497681" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Http-Event-Collector-ignores-JSON-timestamp/m-p/497681&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/HEC-How-to-set-time-on-base-of-a-specific-JSON-field/m-p/515486" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/HEC-How-to-set-time-on-base-of-a-specific-JSON-field/m-p/515486&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;There are several other post covering this. Main point is use raw endpoint or set time field on json's "header" part outside of actual payload.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 08:21:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-consider-quot-time-quot-as-quot-time-quot-on/m-p/646931#M223916</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-06-14T08:21:33Z</dc:date>
    </item>
    <item>
      <title>Re: logstash overwrite _time field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-consider-quot-time-quot-as-quot-time-quot-on/m-p/646935#M223918</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;is it possible to fix it in logstash ? instead in splunk?&lt;/P&gt;&lt;P&gt;how splunk decide what is the "_time"? always consider as receive time?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 08:42:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-consider-quot-time-quot-as-quot-time-quot-on/m-p/646935#M223918</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2023-06-14T08:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: logstash overwrite _time field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-consider-quot-time-quot-as-quot-time-quot-on/m-p/646940#M223921</link>
      <description>&lt;P&gt;As you send it via HEC you must told to splunk which field you want to use as _time otherwise it's used it's own heuristic to try to guess the correct time.&lt;/P&gt;&lt;P&gt;Here is described how this is happening&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/HowSplunkextractstimestamps" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/HowSplunkextractstimestamps&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 09:04:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-consider-quot-time-quot-as-quot-time-quot-on/m-p/646940#M223921</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-06-14T09:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: logstash overwrite _time field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-consider-quot-time-quot-as-quot-time-quot-on/m-p/646981#M223940</link>
      <description>&lt;P&gt;As splunk can guess timestamp is it possible to send data from logstash in somehow that splunk consider e.g field that in json format called “time” consider as _time?&lt;/P&gt;&lt;P&gt;without change splunk settings?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 13:49:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-consider-quot-time-quot-as-quot-time-quot-on/m-p/646981#M223940</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2023-06-14T13:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: logstash overwrite _time field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-consider-quot-time-quot-as-quot-time-quot-on/m-p/647035#M223961</link>
      <description>You should read those above links. Those describe how it should do.</description>
      <pubDate>Wed, 14 Jun 2023 20:21:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-consider-quot-time-quot-as-quot-time-quot-on/m-p/647035#M223961</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-06-14T20:21:04Z</dc:date>
    </item>
  </channel>
</rss>

