Splunk Search

Is _indextime deprecated?

responsys_cm
Builder

I'm trying to see if a clock is off on some of my servers and I want to compare the _time field with the time the event was indexed. From looking around, I thought that _indextime was supposed to give me that. But that field isn't available in my data...

How do I find out when Splunk indexed an event?

Thx.

C

Tags (1)

Stephen_Sorkin
Splunk Employee
Splunk Employee

_indextime is definitely not deprecated. To get it to show, you must rename it to a field name that doesn't begin with an underscore.

Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...