Splunk Search

_time not showing up in data model

jeremiahc4
Builder

I indexed some csv data which has a field called Open Time which winds up being selected as the _time and looks fine via a regular search. I can do timechart based on the data in search.

It breaks down when I throw it into a data model though. _time is not selectable as an auto-extracted attribute in the data model definition. I assume I am missing something. This is preventing me from doing timecharts within pivot.

Tags (3)
1 Solution

sowings
Splunk Employee
Splunk Employee

It sounds like you started from a "root search". Try "root event" instead. In the latter case, _time should appear as one of the auto-extracted fields. I had the same issue.

View solution in original post

sowings
Splunk Employee
Splunk Employee

It sounds like you started from a "root search". Try "root event" instead. In the latter case, _time should appear as one of the auto-extracted fields. I had the same issue.

jeremiahc4
Builder

that was it, must have missed that in the instructions somewhere and couldn't find an existing question that answered it

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...