All Apps and Add-ons

Report for event timestamp & indexed timestamp

satishsdange
Builder

Hey Guys -

I am looking to create a simple report with event timestamp & indexed timestamp information but not able to merge index=xxx & index=_internal. Could someone please help me with search. You may consider any sample data.

Thanks in advance.

Tags (2)
0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

Hello,

Please try this:

 ... | eval indexed_time=strftime(_indextime, "%+") | table indexed_time _time

There isnt a need to combine both indexes as there is always a hidden internal field called _indextime.

You might also find this post helpful: https://answers.splunk.com/answers/42646/showing-indexed-time.html

View solution in original post

0 Karma

jkat54
SplunkTrust
SplunkTrust

Hello,

Please try this:

 ... | eval indexed_time=strftime(_indextime, "%+") | table indexed_time _time

There isnt a need to combine both indexes as there is always a hidden internal field called _indextime.

You might also find this post helpful: https://answers.splunk.com/answers/42646/showing-indexed-time.html

0 Karma

satishsdange
Builder

Is there anyway to include timestamp for data read by UF as well?

Thanks

0 Karma

jkat54
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...