Knowledge Management

collecting data from kvstore to index

mintucs
New Member

while i am collecting from kv store to index

|inputlookup amkc | collect index="game"

the index having time as current time how could we can sync _time with kv store time field

Tags (1)
0 Karma

somesoni2
Revered Legend

Create a field _time explicitly, and assigned the epoch value of your kv time field.

If your timeField from kvstore is already in epoch format, try like this

|inputlookup amkc | eval _time=timeField | collect index="game"

If your timeField from kvstore is no in epoch format, use strftime function to do so, like this (assuming string time format of field timeField is %Y-%m-%d %H:%M:%S, update the same per your format)

|inputlookup amkc | eval _time=strftime(timeField,"%Y-%m-%d %H:%M:%S") | collect index="game"
0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...