Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Setting the timestamp when using the collect command

$
0
0
I am searching yesterday's data and trying to insert it into an index for reporting purposes. I need to take multiple indexed events with various date/time fields and override them with the current date/time for the summary index table. The following search is a very simplified version that illustrates the issue. index=blah | eval _time=now() | collect index=test When I do the search, it inserts yesterday's date/time into the summary index _time field. Is there any way to reassign this? Splunk 6.6.3.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>