Hi,
hi @vijaysri,
Summary index events do have timestamps.
if your saved search results contain a _time field then the timestamp will be set to this field values in the summary index. If _time is not there then timestamp is set to the CURRENT time(when data is parsed) in the summary index.
Retention for the summary index is 5 years and the max data size is 500GB.
If this reply helps you, a like would be appreciated.
hi @vijaysri,
Summary index events do have timestamps.
if your saved search results contain a _time field then the timestamp will be set to this field values in the summary index. If _time is not there then timestamp is set to the CURRENT time(when data is parsed) in the summary index.
Retention for the summary index is 5 years and the max data size is 500GB.
If this reply helps you, a like would be appreciated.