Given free sample http stream data download from splunk website. I got two questions with start time, record time and endtime. (1). is "_time" the recorded time by splunk index? how to output as "H:MM:SS" format. and "HH:MM:SS" format respectfully? example, 18:27.36.257, HH:MM:SS will be 18:27:36, H:MM:SS will be 6:27:36 (2), say, user enter hacker.com/a.js in chrome at 18:27:36, at 18:27:50, a.js start loading, 18:28:59, a.js finished execution, would splunk index capture start time, record time, endtime? what are the fields? thanks
... View more