Hi
How can i add current time to _time filed while reading data from CSV file.
I have added below in Splunk\etc\system\default\props.conf
[csv]
URRENT
TIME_FORMAT = %y-%m-%d %H:%M:%S
But it seems date is taking from file name. My file name is like ABC20140107.
I want current time in _time field.How can i achieve this.
Use this props.conf:
[csv]
DATETIME_CONFIG = CURRENT
regards
Thanks i have added this and solved