We have a log file which contains a 7 digit second timestamp like the below: 08:30:00.2124216
We periodically need to compare sub second times between events, but it looks like the splunk event _time only includes the first 3 second digits like: 08:30:00.212
the problem is when we do a sort by _time, we frequently see events that are out of order like the following: 08:30:00.2124216 08:30:00.2124215 (this should be the reverse)
Anyone know of a way to handle this? Can splunk be configured to recognize a more granular time stamp?