Getting Data In

I have a data that I'm manually ingesting the data from Splunk WEB but I don't have time stamp in my log but I have field that has time but no time in it . so I need that has my time stamp with default 00:00:00:000 has time for me ,how ?

aorkcreate
New Member

I have a data that I'm manually ingesting the data from Splunk WEB but I don't have time stamp in my log but I have field that has time but no time in it . so I need that has my time stamp with default 00:00:00:000 has time for me ,how ?

Tags (1)
0 Karma

varad_joshi
Communicator

You need to look into timestamp assignments. If there is no timestamp at all then you might as well take index time as timestamp. In which case _time field will be populated with index time values. Check more in the URL below.

http://docs.splunk.com/Documentation/Splunk/7.1.2/Data/HowSplunkextractstimestamps

0 Karma

adonio
Ultra Champion

hello there,
can you please elaborate on your challenge?
what exactly are you trying to do?

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...