Hi
I have logstash config that send logs to Splunk HEC.
these data contain field that call "time".
Now question is: Is it possible to consider "time" as "_time" on logstash config?
FYI: i want to consider this time as _time not the time that splunk receive it
Any idea?
Thanks
Hi
There are ways to do it. I point to another answers where it has solved:
There are several other post covering this. Main point is use raw endpoint or set time field on json's "header" part outside of actual payload.
r. Ismo
@isoutamois it possible to fix it in logstash ? instead in splunk?
how splunk decide what is the "_time"? always consider as receive time?
As you send it via HEC you must told to splunk which field you want to use as _time otherwise it's used it's own heuristic to try to guess the correct time.
Here is described how this is happening https://docs.splunk.com/Documentation/Splunk/latest/Data/HowSplunkextractstimestamps
As splunk can guess timestamp is it possible to send data from logstash in somehow that splunk consider e.g field that in json format called “time” consider as _time?
without change splunk settings?