Default Version 1.0
July 23, 2018
July 23, 2018
Splunk Enterprise
Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0
Log in to rate this app
#38 in Generic
This add-on will configure Splunk to not consider an ISO8601 timestamp when generating the index. It will save significant disk space at the cost of not being able to search free text on timestamps. i.e. it's no longer possible to search for terms like '2018'. Normal search by time of course still works. This app will not work in Splunk Cloud. It modifies the `segmenters.conf` and this only supported in on-premises deployments.
Log in to report this app listing.