Hi,
Is there a way to use the import date and time vs. having splunk try to interpret a date in the event? The date in our event is meaningless as far as using it for any data analysis.
There is an attribute in props.conf called DATETIME_CONFIG
which you can set to value CURRENT
and Splunk will treat current time (time of import) as the event timestamp.
[yoursourcetype]
...line breaking configs..
DATETIME_CONFIG = CURRENT
There is an attribute in props.conf called DATETIME_CONFIG
which you can set to value CURRENT
and Splunk will treat current time (time of import) as the event timestamp.
[yoursourcetype]
...line breaking configs..
DATETIME_CONFIG = CURRENT
Perfect! Thanks Somesoni2!