Getting Data In
Highlighted

How to set the time events were indexed as the event timestamp, not the time the logs were written?

Explorer

I would like to read log data by the time the log was ingested, not the time the log was written. For example, give me logs ingested by Splunk in the last 30 seconds. This is almost like a real-time ingestion, except I'm not looking at the log entry time.

0 Karma
Highlighted

Re: How to set the time events were indexed as the event timestamp, not the time the logs were written?

Legend
0 Karma
Highlighted

Re: How to set the time events were indexed as the event timestamp, not the time the logs were written?

Explorer

I can't get to the link provided.

Thanks

0 Karma
Highlighted

Re: How to set the time events were indexed as the event timestamp, not the time the logs were written?

Explorer

That's it! Thank you.

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.