After uploading into splunk, am getting the view which contains fields _time, source, host, sourcetype,punct and _raw.
Question1) The date in log shows Apr 28 2013 11.05 but in the splunk under _time field it shows as "4/28/2013 12:55:33".How to solve this issue?
Question2) I need to count no of _raw fileds which contains data and which is blanks using the time stamp.for example at the time of Apr 28 2013 11.05, count of _raw fields having some data and count of _raw fields does not having any data or blank.How to do this?
Sorry i am not able to attach the image or screen shot of splunk view with this query since am getting error.
Please share any mail id so that i can provide sample of splunk view to understand better if need.