All Apps and Add-ons

Report for event timestamp & indexed timestamp

satishsdange
Builder

Hey Guys -

I am looking to create a simple report with event timestamp & indexed timestamp information but not able to merge index=xxx & index=_internal. Could someone please help me with search. You may consider any sample data.

Thanks in advance.

Tags (2)
0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

Hello,

Please try this:

 ... | eval indexed_time=strftime(_indextime, "%+") | table indexed_time _time

There isnt a need to combine both indexes as there is always a hidden internal field called _indextime.

You might also find this post helpful: https://answers.splunk.com/answers/42646/showing-indexed-time.html

View solution in original post

0 Karma

jkat54
SplunkTrust
SplunkTrust

Hello,

Please try this:

 ... | eval indexed_time=strftime(_indextime, "%+") | table indexed_time _time

There isnt a need to combine both indexes as there is always a hidden internal field called _indextime.

You might also find this post helpful: https://answers.splunk.com/answers/42646/showing-indexed-time.html

0 Karma

satishsdange
Builder

Is there anyway to include timestamp for data read by UF as well?

Thanks

0 Karma

jkat54
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...