Getting Data In

Ingest events from AWS SQS but how to config timestamp field in props.conf

jerrin
Explorer

I am a newbie and I have understood basics on how to use the props.conf. But I dont find any doc on ingesting events from AWS SQS then how do I config the props.conf file to include event_timestamp as _time.

Definition says in props.conf is always based on source | sourcetype | host; correct me here if I am wrong. But in case of AWS SQS, all the 3 values are same for more than 1 index. I want this change only for 1 specific index.

Appreciate some insight

sourcetype: aws:s3:accesslogs
source: "s3://jjacob-stats/prod/*.gz"
host: ip-10-0-0-255
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...