Getting Data In

How to use source file modification time instead of guessed date in events?

splunkreal
Motivator

Hello guys,

how to use the source file modification date instead of "guessed" or extracted timestamp from csv file?

I'm using specific sourcetype and extracting fields at search time (fields transformations)

Thanks.

Splunk 7.3.4

 

* If this helps, please upvote or accept solution if it solved *
0 Karma
Get Updates on the Splunk Community!

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...

Introducing New Splunkbase Governance!

Splunk apps are essential for maximizing the value of your Splunk Experience. Whether you’re using the default ...

3 Ways to Make OpenTelemetry Even Better

My role as an Observability Specialist at Splunk provides me with the opportunity to work with customers of ...