Splunk Enterprise

Index parsing order

sean_aditum
Engager

Hi All,

Does anyone know the exact order index parsing is completed?  Reason being, i have a 1 log file that i'd like to parse two different time stamps from.  I was going to assign source type A to it, then at parsing use transforms to either assign source type "A:A" or "A:B" to it and pull the time from there.  However it appears timestamps are pulled before this step.  

Thoughts?

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

This is a great reference: https://www.aplura.com/assets/pdf/props_conf_order.pdf

Note that once Splunk starts processing a sourcetype it will continue the same processing even if the sourcetype changes.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...