Hello fellow Splunkers!
Apologies if this has been documented or answered elsewhere - I couldn't find the answer...
I was discussing the following documentation page with a colleague regarding indexing events with a time resolution in nanoseconds.
Configure timestamp recognition - Enhanced strptime() support
It says that you can use enhanced strptime expressions in conjunction with the TIME_FORMAT attribute in your props.conf to configure timestamp parsing. This includes parsing timestamps in nanoseconds by using the %9N expression.
My question is, even if you successfully index the timestamp in nanoseconds, when the event is displayed in Splunk search results will it just display the timestamp to three decimal places (milliseconds) instead of nine decimal places (nanoseconds)?
Does anyone have experience indexing events with time resolutions in nanseconds who could comment?
Thanks in advance for your help!
... View more