Knowledge Management

How do I override _time in a saved search that saves to a summary index, such that the time the values goes in at is recognized when searching through the summary index?

briancronrath
Contributor

I am using a saved search that pulls in data from an external source with it's own time format. I've converted the format to match what I see when I output _time, and eval'd _time to be that converted value, but it doesn't seem to be getting recognized, because whenever the data comes in and I search on it, all the data just gets put to the beginning of today. Is there an extra step I'm missing in order to get _time to be overridden with my own values?

0 Karma

somesoni2
Revered Legend

You need to convert your custom date string to epoch and assign to field _time in the events. We may be more helpful if you could provide your current search, some sample values etc.

briancronrath
Contributor

Ahh that was my issue, I was using strftime after strptime to format it how I see _time when I output it through the UI, but I should have just been keeping it in epoch format. Thank you somesoni2 !

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...