Trying to index a native_stdout.log that has no dates in the first line and only has time-stamps.
07:26:49,602 INFO [ServerImpl]
07:26:49,602 INFO [ServerImpl]
07:26:49,602 INFO [ServerImpl]
07:26:49,602 INFO [ServerImpl]
07:26:49,602 INFO [ServerImpl]
Splunk indexed the file by using the file modified date. Is this the expected behavior when the log file has no dates?
↧