Hi Team,
I have indexed the file as current timestamp but would like to execute the query by taking the filename timestamp as _time will that be possible now? if yes, how do we do that.
|eval _time=timestamp
You can overwrite the _time field at any point in your search pipeline. Just remember that it's supposed to be a numeric field containing number of seconds since epoch.
For example,
index=aaa | streamstats count as _time
will make your results start at Jan 1st 1970 at midnight and will "trickle" your events one per second.
One caveat though - since the _time field would be re-set later in the process, you can't use this value for initial timerange selection. (You can add conditions on time later in the SPL though).
Hi @Borntowin,
Hi @Borntowin,
the only soilution is the one that you can find at https://community.splunk.com/t5/Getting-Data-In/Timestamp-from-file-name/m-p/67233 or at https://www.splunk.com/en_us/blog/tips-and-tricks/configure-splunk-to-pull-a-date-out-of-a-non-stand... but I didn't personally tested it.
Otherwise it's possible a porkaround that you can find at https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-timestamp-from-a-filename-at-index-...
Ciao.
Giuseppe