Splunk Search

Change the Fschange indexing date


Is it possible to change the Fschange indexing date, not time?

My need is: if a file is added/modified/deleted the date January 17 2012 at 09:30, is it possible to index it the date January 16 2012 at 09:30?

Workarond: leaving the indexing real date/time, is it possible add a new field with the indexing date -1 day?

Thanks a lot.

Tags (3)
0 Karma


I dont think there is a way to alert the date in fschange. The date is taken from the local system time of the indexer.

0 Karma