Hi I currently have the following json in splunk:
{"first_name": "john", "last_name": "black", "timestamp": "2013-09-09 08:00:00", "age": "26", "activity": "start"}
The issue is that splunk should read the timestamp and use that for the time the event is logged. However, it simply is taking the time the event was indexed into the system instead. There is no problem with the other fields, they are parsed fine by splunk.
How should I make splunk recognise the timestamp in this json? Is it possible for it to be done automatically if the format the timestamp is written in it changed?
Anthony