Getting Data In

Configure Event Timestamp

rantravee
Path Finder

Hi,

I would like to know how to configure Splunk so that for each event that I'm feeding to it the system time is used as the event timespamp.

I need to do this because the JSON objects that are fed to Splunk contain keys/value that describe the time(in millies) of some things and this makes Splunk to mismatch the event timestamps for some value that it finds within the JSON object.

Any hint would be greatly appreciated,

0 Karma
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

You can set it in props.conf. See the docs for details: http://docs.splunk.com/Documentation/Splunk/latest/admin/propsconf

props.conf
[mysourcetype]
DATETIME_CONFIG = CURRENT

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

You can set it in props.conf. See the docs for details: http://docs.splunk.com/Documentation/Splunk/latest/admin/propsconf

props.conf
[mysourcetype]
DATETIME_CONFIG = CURRENT

rantravee
Path Finder

Worked for me. Thanks a bunch !

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...