I'm building a Splunk App and would like to create some timecharts and other visualizations.
However, I would like to use the timestamp present in the data I'm sending to the app instead of the system time.
My data has timestamps as given below:
1/1/2000 12:00:00 AM
1/1/2016 12:00:00 AM
4/29/2019 5:32:00 PM
3/16/2018 9:41:00 PM
I want to modify the default Splunk timestamp to the entries from my data.
You will likely need to configure your TIME_FORMAT in props.conf. However, without seeing the data it's hard to say. You should take a read through https://docs.splunk.com/Documentation/Splunk/7.3.0/Data/Configuretimestamprecognition this should help you in isolating down timestamp in your data.