Agreed. The term absolute time shouldn't have been used in the answer. I have edited it. Was thinking in a different direction, typed half of the answer and then the chain of thoughts changed. Since Splunk handles the missing %H:%M:%S gracefully, it should with the date too.
... View more