Getting Data In

Splunk SDK: Is there a way to set the time of an event created from Submit?

ConnorG
Path Finder

I'm currently in the process of sending data to the Splunk server through the C# SDK.

The time for every event sent to the server is based on when the server received the event, and not my own timestamp that is attached to the event in a field.

Here's an example of what I'm doing:

        Receiver splunkReceiver = new Receiver(service);

        var args = new Args();
        args.Add("host", "win-5ja2nu0k88c");
        args.Add("source", "dynaTrace");
        args.Add("sourcetype", "Monitoring");

        splunkReceiver.Submit("main", args, "EventType=4 Keywords=Classic, RecordNumber=number, timestamp = 9/04/13");

Is there a way to set set the time of the event created from this Submit? I would want it to be equal to my timestamp field. Perhaps through a specific arg?

Tags (3)
1 Solution

Damien_Dallimor
Ultra Champion

I tried reformatting your message a bit and it works :

Thu Sep 04 2013 12:47:31 EventType=4 Keywords=Classic RecordNumber=number

Alternatively , you could declare timestamp extraction rules in props.conf for your sourcetype "Monitoring"

View solution in original post

Damien_Dallimor
Ultra Champion

I tried reformatting your message a bit and it works :

Thu Sep 04 2013 12:47:31 EventType=4 Keywords=Classic RecordNumber=number

Alternatively , you could declare timestamp extraction rules in props.conf for your sourcetype "Monitoring"

Damien_Dallimor
Ultra Champion

Please "accept" the answer. Thanks.

0 Karma

ConnorG
Path Finder

That worked wonderfully. Thanks much for the assistance sir.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...