i read this following link
Now i have one question in my mind,what happen when more than 10 records has same time stamp in database,then how splunk will handle this. it take which record came fast?
i know this is silly question,but i want to clear how process will go.
Splunk can index up to 100,000 records with the same time stamp. After that we'll start to increment the timestamp. For a detailed discussion of this, please see:
View solution in original post