My log format is such that the time stamp is not recognized, as such the (bold) timestamp shows up as the time the message was ingested rather than the actual time. I am parsing out the actual date/time with an extractor and can see it in my search results, I’m struggling however to override the “Timestamp”.
I’m trying to follow this Set timestamp with pipeline solution but I’m not entirely sure I get the process. I created a pipeline which has a Stage 0 to which my rule is attached, I guess I don’t entirely understand why this is attached to a “Stream”.
Right now “Timestamp” isn’t getting overridden, I added a second new field to my rule to see if it is created and it is not, as such I suspect maybe the rule is correct (I copied it from the link above) but that I don’t have it hooked in correctly.
Is this the right procedure… create a Pipeline, Create a Rule, Add a Stage 0 to the Pipleline and specify the rule, attach the Pipeline to the “All Messages” Stream?