Getting Data In
Highlighted

Can I make a field which contains the number of the entry, as a substitute for timestamp?

New Member

I would like to experiment with entries in which time is mentioned as 1,2,3, .... , n; where the nth entry is the latest. Is this possible?

0 Karma
Highlighted

Re: Can I make a field which contains the number of the entry, as a substitute for timestamp?

Legend

Look at streamstats command. You can use that to add a "counter" in reverse order to your events. Something like this may work base search | reverse | streamstats count

http://docs.splunk.com/Documentation/Splunk/6.5.1/SearchReference/Streamstats

0 Karma