I'm using "collect" to send events to a summary index. Collect seems to put its execution time into the _time field of the summary indexed events. If I wanted to have a field in the event data used as the _time value for the summary index, how would I do that?
Thanks.
Craig
Yes, you can set the value of the _time field before the collect.
Example:
... | addinfo | eval _time=info_max_time | collect ...
you can use any eval function to calculate the _time value.