Splunk Search

Is it a problem to add a new input at the same time your are already downloading events?

edigilink
Explorer

Hello everyone,

I am having a problem which the _time is being populated with wrong date and time even if it is well specified.

I tried many approaches to isolate all the variables and noticed that for some reason the "add-on indexing process" get lost when you add a new input while already downloading some events.

Does it make any sense? Someone already faced it?

I really appreciate your comments.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...