All Apps and Add-ons

Report for event timestamp & indexed timestamp

satishsdange
Builder

Hey Guys -

I am looking to create a simple report with event timestamp & indexed timestamp information but not able to merge index=xxx & index=_internal. Could someone please help me with search. You may consider any sample data.

Thanks in advance.

Tags (2)
0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

Hello,

Please try this:

 ... | eval indexed_time=strftime(_indextime, "%+") | table indexed_time _time

There isnt a need to combine both indexes as there is always a hidden internal field called _indextime.

You might also find this post helpful: https://answers.splunk.com/answers/42646/showing-indexed-time.html

View solution in original post

0 Karma

jkat54
SplunkTrust
SplunkTrust

Hello,

Please try this:

 ... | eval indexed_time=strftime(_indextime, "%+") | table indexed_time _time

There isnt a need to combine both indexes as there is always a hidden internal field called _indextime.

You might also find this post helpful: https://answers.splunk.com/answers/42646/showing-indexed-time.html

0 Karma

satishsdange
Builder

Is there anyway to include timestamp for data read by UF as well?

Thanks

0 Karma

jkat54
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...