how can i force the timestamp of an event to be the receive time and ignore all other timestamps in the event.
the solution is to disable the timestamp processor:
"Splunk does not look at the text of the event for the timestamp. Instead, it uses the event's "time of receipt"
View solution in original post