I don't know how to fully solve the OP's issue, but I did figure out how to do it with an epoch that's showing up in the event. Using an IDX transform on the sourcetype. (For me, I had the epoch time at the start of _raw. [set_x-balancer_time] SOURCE_KEY = _raw REGEX = ^(\d{10}\.?\d*)\s FORMAT = $1 DEST_KEY = _time DEST_KEY = _time - requires the timestamp to be in epoch format, so in order to get that to work with another timestamp you'd have to find a way to change it into epoch.
... View more