while i am collecting from kv store to index
|inputlookup amkc | collect index="game"
the index having time as current time how could we can sync _time with kv store time field
Create a field _time explicitly, and assigned the epoch value of your kv time field.
If your timeField from kvstore is already in epoch format, try like this
|inputlookup amkc | eval _time=timeField | collect index="game"
If your timeField from kvstore is no in epoch format, use strftime function to do so, like this (assuming string time format of field timeField is %Y-%m-%d %H:%M:%S, update the same per your format)
|inputlookup amkc | eval _time=strftime(timeField,"%Y-%m-%d %H:%M:%S") | collect index="game"