Knowledge Management

How do I override _time in a saved search that saves to a summary index, such that the time the values goes in at is recognized when searching through the summary index?

briancronrath
Contributor

I am using a saved search that pulls in data from an external source with it's own time format. I've converted the format to match what I see when I output _time, and eval'd _time to be that converted value, but it doesn't seem to be getting recognized, because whenever the data comes in and I search on it, all the data just gets put to the beginning of today. Is there an extra step I'm missing in order to get _time to be overridden with my own values?

0 Karma

somesoni2
Revered Legend

You need to convert your custom date string to epoch and assign to field _time in the events. We may be more helpful if you could provide your current search, some sample values etc.

briancronrath
Contributor

Ahh that was my issue, I was using strftime after strptime to format it how I see _time when I output it through the UI, but I should have just been keeping it in epoch format. Thank you somesoni2 !

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...