Where Timestamp value is stored?
We have seen how the timestamp is assigned. But where it is actually stored in Splunk.
In Splunk, there is a field called _time. The extracted timestamp value is stored in this field.
Sometimes, it will be displayed as “Time” with capital T or _time, but behind the screen, both are referring to the same field which is “_time”
🆓🆓Free Masterclasses: (With live session 👨💻 at the end)🆓🆓
Splunk Timestamp Extraction Masterclass 101:
https://splunk.softmania.in/course/sp...
Scenario-based Splunk Admin Use Cases - Part 1:
https://splunk.softmania.in/course/sc...
Splunk Search Commands Masterclass 101:
https://splunk.softmania.in/course/sp...
👑👑Soft Mania Premium Subscription👑👑
One-time Subscription with Lifetime access to all masterclasses.
For more details, visit: https://splunk.softmania.in/course/so...
(Subscription charges will spike by 40% on 01-Mar-2024. 📈)
#splunk #splunkadmin #splunkblogs #splunkengineer #splunklife #softmania #splunkmania