Hello, I'm trying to determine if we are getting all the TrendMicro logs by comparing what's in Splunk and what's in Trend. There are 2 date/time stamps in the Splunk logs which I assume 1 is the actual event date/time and the other is the Splunk index date/time. I've ran the following 2 searches which return the same date_time stamps but I would expect to be different since the 2 date/times are different. Times: Aug 28 11:18:43 x.x.x.x Aug 28 15:12:19 index=trendmicro | eval mytime=strftime(_time,"%Y-%m-%dT%H:%M:%S.%Q %Z") 2020-08-28T11:18:43.000 EDT index=trendmicro | eval mytime=strftime(_indextime,"%Y-%m-%dT%H:%M:%S.%Q %Z") 2020-08-28T11:18:43.000 EDT How can I pull/report on both of these fields with both of the date_time stamps so we can determine we are getting all logs as well as if the indexer(s) are under resourced?
... View more