Splunk Search

Change the Fschange indexing date

Cris
Explorer

Is it possible to change the Fschange indexing date, not time?

My need is: if a file is added/modified/deleted the date January 17 2012 at 09:30, is it possible to index it the date January 16 2012 at 09:30?

Workarond: leaving the indexing real date/time, is it possible add a new field with the indexing date -1 day?

Thanks a lot.

Tags (3)
0 Karma

hedgehog
Explorer

I dont think there is a way to alert the date in fschange. The date is taken from the local system time of the indexer.

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...