My index time is 7/6/20 3:37:42.210 PM
My event time is 07/06/20 10:37:42.210 CDT
My TIME_FORMAT=%x %H:%M:%S.%3N%Z
But still, by referencing the above time, we can see the latency between index time and event time. Please suggest how to resolve this.
@richgalloway event time is CDT. So what i need to do.
@richgalloway So you want me to use only TIME_FORMAT=%x %H:%M:%S.%3N and remove %Z?
@richgalloway Yes i will check, please let me know if source system and that source system logs are different timestamps, then it will create any latency ? And how to solve that?