Splunk Enterprise

Index parsing order

sean_aditum
Engager

Hi All,

Does anyone know the exact order index parsing is completed?  Reason being, i have a 1 log file that i'd like to parse two different time stamps from.  I was going to assign source type A to it, then at parsing use transforms to either assign source type "A:A" or "A:B" to it and pull the time from there.  However it appears timestamps are pulled before this step.  

Thoughts?

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

This is a great reference: https://www.aplura.com/assets/pdf/props_conf_order.pdf

Note that once Splunk starts processing a sourcetype it will continue the same processing even if the sourcetype changes.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...