Thank both of you for your suggested solutions!
@adonio Good idea, thank you, I will test this with eval in the props.conf!
@jarizeloyola Thanks! I am using ingest_eval for another source which timestamp can only be found in the filename, and it works great! However, I see splunkd timestamp errors for that source, so I have to check if inges_eval works in a way there will still have timestamp issues generated even if OK, or if it is something else!
... View more