Hi i have a problem with automatically time sort i want disable _time sort because in my log they have some event which show previous event time they give previous time to give details. but splunk take this time and sort automatically
Because of automatic sorting they change the place of some event so i want completely disable Automatically time sort.
1) I try fields - _time , Not work they not show _time field but sorting happen
2) i try
disabled = true
in file C:Program Files/Splunk/etc/system/default/times.conf
they also not work
4) i try
| sort _indextime
5) i try
| sort - _indextime
6) i try
| sort + _indextime
7) i try sort 0 - _indextime
Nothing is work if i use _indextime then they give reault 1000 only and other so blank.