Adding below attribute in props.conf to ignore the time stamp from the event isn't working.
DATETIME_CONFIG = NONE
MAX_TIMESTAMP_LOOKAHEAD didn't work either
MAX_TIMESTAMP_LOOKAHEAD = 0
Any other way to specify Splunk not to look for time stamp from the event?
Hello,
Could you use
DATETIME_CONFIG =CURRENT
Make sure they are placed in the receiving indexers if no heavy forwarder is used.
Thanks
Hello,
Could you use
DATETIME_CONFIG =CURRENT
Make sure they are placed in the receiving indexers if no heavy forwarder is used.
Thanks