Knowledge Management

How to collect summary events with a new sourcetype and server time

proylea
Contributor

I want to extract certain events into the same index with a different sourcetype, this is simple, but I would like to change the timestamp of the collect event to server time.

This is the search I am using but it keeps the original timestamp of the event.

index="cartt" | tail 100 | collect addtime=false index=cartt host=CARTT source=cartt_deleted sourcetype=cartt_deleted
0 Karma

micahkemp
Champion

Why do you want to change the sourcetype?

You can use [source:] in props.conf to create search time customizations for summary data.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

How about this?

index="cartt" | tail 100 | eval _time=now() | collect addtime=false index=cartt host=CARTT source=cartt_deleted sourcetype=cartt_deleted
---
If this reply helps you, an upvote would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

<P style=" text-align: center; "><span class="lia-inline-image-display-wrapper lia-image-align-center" ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

<FONT size="5"><FONT size="5" color="#FF00FF">Get the latest news and updates from the Splunk Community ...