Essentially I’m trying to replace the ingestion timestamp with the actual timestamp in the logs. I’ve read many of the posts about this but I don’t seem to be making any progress.
As you can see in the screenshot below the Timestamp(far left) and timestamp(in the middle) are the same and are the time of ingestion, not the time of the log. I’ve created an extractor to copy the timestamp from the log and put it into the timestamp_orig(far right). As you can see in the screenshot.
I’ve already tried to copy/replace in the extractor to the timestamp field but that doesn’t change the timestamps.
I’ve then tried to make a pipeline to do it.
rule “parse right timestamp”
let new_date = parse_date(to_string($message.timestamp_orig));
That doesn’t seem to be doing anything to my timestamps.
I feel like I’m missing something fairly simple and help would be much appreciated.