I have a data that I'm manually ingesting the data from Splunk WEB but I don't have time stamp in my log but I have field that has time but no time in it . so I need that has my time stamp with default 00:00:00:000 has time for me ,how ?
You need to look into timestamp assignments. If there is no timestamp at all then you might as well take index time as timestamp. In which case _time field will be populated with index time values. Check more in the URL below.
http://docs.splunk.com/Documentation/Splunk/7.1.2/Data/HowSplunkextractstimestamps
hello there,
can you please elaborate on your challenge?
what exactly are you trying to do?