Hi @PickleRick , I completely follow you time sync (NTP) is crucial on all layers of data sources towards Splunk if correlations shall work and make sense. I've worked a lot with time on quite a few customers sites, and way too many don't have control over their time and timezone. To the question if this would make sense or not, there is no doubt to me, that it would, and for more than one reason: Troubleshooting (mainly) time skewing latency queuing Just to name a few. As of today it not possible to measure the latency between tiers, and you'll have to use other methods to find bottlenecks etc. Yes - additional fields will be needed, and multi-value is a no-go and a mess as I see it. The challenge is, as I see it: How to add additional fields to cooked data (which they will be on the first HFwd), do you know how to do that? Is it possible to create an app on ie. the indexer (last tier), that will add the arrival at the indexer. PS. I'm know this is the _indextime if, and only if there is no HFwd between the UF and the Indexer, else _indextime will be set at first HFwd, which is useless for this purpose. @isoutamo - Your idea about adding an idea at splunk is fine, but my experience with it is no so positive, it's too slow in my opinion. The smartest and fastest ideas comes here 👍
... View more