Splunk AppDynamics

Log Analytics Timestamp

Sandor_Bihary
Path Finder

Hi All!

We are using the syslog functionality of the analytics agent to collect data.

The logs may be from the past so the creation timestamp is also in the past.

My problem is that AppD always considers the ingestion date as the "timestamp". We can extract the timestamp from the message with regexp but we are not able to use it for charting.

So when we bulk load logs into AppD we try charting we can use only the "ingestion" timestamp so the chart/widget won't be accurate at all.

Do you know who to work around this? We want to use customer timestamps so that we can create accurate charting.

Best,

Sandor

Labels (1)
0 Karma

Sandor_Bihary
Path Finder

Hi All!

I just re-up this thread.

Does anyone know how to alter the timestamp when we feed in data into the log analytics?

0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...