I've got certain events that I want to send to collect. I see the addtime option (defaults to true). What does it do?
My assumption was that setting it to false (addtime=f) uses the _time of the original event, but that doesn't seem to be the case. No matter what I use, t or f, I get a timestamp of the current time when my search was piped to collect. For example:
mysearch for two files | diff | collect index=summary addtime=f
(The search outputs just fine with the correct date when I append | addinfo to the end of the search above.)
Splunk version 4.1.4.