Getting Data In

Index time mapping in inputs.conf

DataOrg
Builder

I have two fileds TIME and Last execution TIME.

In input.conf i have mapped TIME field to use a index time(_time) but in some cases it take the last execution TIME.

how to overcome this?

0 Karma

FrankVl
Ultra Champion

Can you please provide the actual config you have and also some sample data? I don't understand what you mean with mapping time in inputs.conf.

0 Karma

akocak
Contributor

I think he means using indextime as timestamp in inputs.conf 🙂

0 Karma

FrankVl
Ultra Champion

That would still be controlled through props.conf and not inputs.conf, right?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

yes you are right. I dont think we can control timestamp of event using inputs.conf.

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...