Well this one is interesting. How can splunk index something before it knows about it 😛
That's not too hard.. _time is derived from the timestamp, which could be in the past or in the future(!). _indextime is the time the event arrives at the indexer.
View solution in original post
Makes sense, sounds like i need to be looking at what the _time data is for the events that are coming in.