How to use source file modification time instead of guessed date in events?


Hello guys,

how to use the source file modification date instead of "guessed" or extracted timestamp from csv file?

I'm using specific sourcetype and extracting fields at search time (fields transformations)


Splunk 7.3.4


