Hi,
How we can extract time from the log event and then index ?
As Splunk shows different time stamp on indexer but time stamp in log event are different.
Please help.
Hi @pankajupadhyay,
probably Splunk cannot correctly recognize timestamps, so you have to give to Splunk some additional information, for a sourcetype:
you can find more infos at https://docs.splunk.com/Documentation/Splunk/8.1.1/Data/Configuretimestamprecognition
If you share some sample of your data I could help you in this job.
Ciao.
Giuseppe