@Raja_Selvaraj DATETIME_CONFIG = CURRENT should work normally. But observed few times with monitor input, Splunk still scans the event content or file metadata (modtime) to determine _time, even if DATETIME_CONFIG = CURRENT is set. Are you using monitor input? But you can use the modification at search time. Eg: BASE_SEARCH
| eval _time = now() Regards, Prewin Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!
... View more