Hi everyone,
I would want to ask if I can create a field alias for _indextime and _time then set this alias as a default field for all sourcetype?
Hi @Shihua,
it isn't a good idea because many commands as timechart run using _time, in addition you should do this for all sourcetypes! and I'm not sure that's possible!
then why do you want to do this?
you have these fields in epochtime, so you can use them for calculations and _time is automatically displayed in human readable, so why?
if you don't like the fieldname _time, you can rename it at the end of the searches.
You could create at index time a new field from them, but why?
Ciao.
Giuseppe
Hi @Shihua,
it isn't a good idea because many commands as timechart run using _time, in addition you should do this for all sourcetypes! and I'm not sure that's possible!
then why do you want to do this?
you have these fields in epochtime, so you can use them for calculations and _time is automatically displayed in human readable, so why?
if you don't like the fieldname _time, you can rename it at the end of the searches.
You could create at index time a new field from them, but why?
Ciao.
Giuseppe
Hi @Shihua ,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉