Getting Data In
Highlighted

Negative Index Delay

Builder

Well this one is interesting. How can splunk index something before it knows about it 😛

alt text

0 Karma
Highlighted

Re: Negative Index Delay

Communicator

That's not too hard.. _time is derived from the timestamp, which could be in the past or in the future(!). _indextime is the time the event arrives at the indexer.

View solution in original post

Highlighted

Re: Negative Index Delay

Builder

Makes sense, sounds like i need to be looking at what the _time data is for the events that are coming in.

0 Karma