I am reading values from DB and _time column get filled in unexpected way.
Is there any way to fill the _time time with current date and time while reading the data from DB.
Thanks
I use splunk DB connect option.The difficulty i am facing is my table also doesnt have a date or time column where i can map to splunk to Timestamp column using splunk web
See http://docs.splunk.com/Documentation/Splunk/6.0.1/admin/Propsconf, search for DATETIME_CONFIG
.
Set DATETIME_CONFIG = NONE
in your inputs.conf
file, or in the Advanced Mode tab when you create the input in Splunk Web.
How is _time being set currently? How are you reading the DB?