Hi,
By default, if no timestamp exist in a field, Splunk defaulting timestamp of previous event
On one hand, I do want Splunk to do it, but on the other hand I don't want Splunk to treat it as a "Timestamp Parsing Issues" in the Data quality.
Is there any way explicitly to tell Splunk to do it? I just want Splunk to treat it as error.
Thanks