I have a simple file that is generated by a script for which I do not have a control. The content of the file is like below
Splunk can parse data well using sourcetype=json_no_timestamp
As a default the timestamp for the indexed data is the current system time
Is there a way I can modify the date time for this particular input (I am using file monitor)? I would like the date stamp to be 1 day behind than the current system time, as data in the file actually represents yesterday's information and not today's.
Thank you so much for such a prompt response. I tried this in props.conf, and it appears that splunk does not recognise time format any more after applying this conversion in props.conf for this sourcetype
Could this be because of strftime converts timestamp to string?