All Apps and Add-ons

Splunk Add-on for GCP: Changing index time from date of ingestion to an already present fields

Théophane_GUE
Loves-to-Learn Lots

Hello Splunkers,

I m currently implementing a connection from multiple GCP Buket to Splunk enterprise.
The Add-on automatically index the datas from those buckets on the _timestamps it get them (So if I have a list of transactions from mars to november 2023, that are forwarded today, they will still be index at the same time.
However, I would like for some of those datas to be indexed using a timefields present in the data, depending on the apps that use them (For example App 1 has a time fields named "Start_date" and app 2 has another one named "end_date")
Unfortunately, i cant think of a way to do it, maybe in the props.conf file, but I'm not sure.

Any advices? Thanks

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...