Hello guys,
how to use the source file modification date instead of "guessed" or extracted timestamp from csv file?
I'm using specific sourcetype and extracting fields at search time (fields transformations)
Thanks.
Splunk 7.3.4