Splunk Search

How splunk decide date/time in _time field?

jangid
Builder

How splunk will decide for date/time in _time field?

I am getting strange date/time.

In first event I don't have any date/time information splunk will use event generate date time.

In second event I have several date/time field splunk pickup date from one of the field and for time it is using event generate time.

Is it right behavior?
If I want educate to splunk on specific date/time based on the eventtype, What should I do?

Tags (3)
1 Solution
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...