Getting Data In

Index time mapping in inputs.conf

DataOrg
Builder

I have two fileds TIME and Last execution TIME.

In input.conf i have mapped TIME field to use a index time(_time) but in some cases it take the last execution TIME.

how to overcome this?

0 Karma

FrankVl
Ultra Champion

Can you please provide the actual config you have and also some sample data? I don't understand what you mean with mapping time in inputs.conf.

0 Karma

akocak
Contributor

I think he means using indextime as timestamp in inputs.conf 🙂

0 Karma

FrankVl
Ultra Champion

That would still be controlled through props.conf and not inputs.conf, right?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

yes you are right. I dont think we can control timestamp of event using inputs.conf.

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...