Splunk Search

How to change the timestamp of duplicate events


I tried to change the time stamp of duplicate events. Can any one suggest me a solution.

Tags (1)
0 Karma


I don't think you can change the timestamp after indexing. Pls try to remove ingesting duplicate event if you can.

0 Karma
Get Updates on the Splunk Community!

Splunk Community Platform Survey

Hey Splunk Community, Starting today, the community platform may prompt you to participate in a survey. The ...

Observability Highlights | November 2022 Newsletter

 November 2022Observability CloudEnd Of Support Extension for SignalFx Smart AgentSplunk is extending the End ...

Avoid Certificate Expiry Issues in Splunk Enterprise with Certificate Assist

This blog post is part 2 of 4 of a series on Splunk Assist. Click the links below to see the other ...