A default field that represents time information in an event. Most events contain timestamps. In cases where an event does not contain timestamp information, the Splunk platform attempts to assign a timestamp value to the event at index time.

The Splunk platform uses timestamps to correlate events by time, to create the timeline histogram in Splunk Web, and to set time ranges for searches.

Related terms

For more information

In the Knowledge Manager Manual:

In Getting Data In: