I'm having an issue with NTP, so the date and time of the records sent by the Operating Systems are all wrong. I want to see/or sort my data within Splunk by the Date/Time the record was received by the Splunk daemon.
Is this possible?
Try using _indextime. It has to be assigned to a variable before it can be used in commands. Like this
your base search | eval sortTime=_indextime | sort sortTime | table ...
Are you looking for the internal _indextime field?