I got a question regarding the field indexed by splunk when an event is received on splunk server.
I would like to index and use the timestamp present into the logs I get from multiple sources.
All those logs are stored into the default DB.
There's 3 kind of timestamps present in the 3 diffrents logs source which look like this :
1343250669001 => This is epoch time
Jul 23 12:09:43
3 eventtype has been created for each.
Splunk is currently indexing these logs at the time it were received on the splunk server.
The purpose would be to do search on splunk from these events using the time present in the logs file.