Getting Data In

Negative Index Delay

paimonsoror
Builder

Well this one is interesting. How can splunk index something before it knows about it 😛

alt text

0 Karma
1 Solution

gwobben
Communicator

That's not too hard.. _time is derived from the timestamp, which could be in the past or in the future(!). _indextime is the time the event arrives at the indexer.

View solution in original post

gwobben
Communicator

That's not too hard.. _time is derived from the timestamp, which could be in the past or in the future(!). _indextime is the time the event arrives at the indexer.

paimonsoror
Builder

Makes sense, sounds like i need to be looking at what the _time data is for the events that are coming in.

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...