I'm having an issue with NTP, so the date and time of the records sent by the Operating Systems are all wrong. I want to see/or sort my data within Splunk by the Date/Time the record was received by the Splunk daemon.
Is this possible?
Try using _indextime. It has to be assigned to a variable before it can be used in commands. Like this
your base search | eval sortTime=_indextime | sort sortTime | table ...
Hi @hartcl1
Are you looking for the internal _indextime field?
http://docs.splunk.com/Documentation/Splunk/6.3.3/Knowledge/UseDefaultFields#Internal_fields