- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk Summary Index : How to include actual time in summary index
beriwalnishant
Path Finder
01-10-2022
02:52 AM
Hi Team,
I was comparing the Summary Index transaction time with the live Splunk server transaction time. I see all transactions collected in 15min bucket keep the same time and override the actual transaction time.
Is there a way to retain the original time while still keeping the count going in buckets define?
Nishant
