Hi All,
Does anyone know the exact order index parsing is completed? Reason being, i have a 1 log file that i'd like to parse two different time stamps from. I was going to assign source type A to it, then at parsing use transforms to either assign source type "A:A" or "A:B" to it and pull the time from there. However it appears timestamps are pulled before this step.
Thoughts?
This is a great reference: https://www.aplura.com/assets/pdf/props_conf_order.pdf
Note that once Splunk starts processing a sourcetype it will continue the same processing even if the sourcetype changes.