I am new to Splunk.
What do the indexed fields
Since one report the company asks for from our archived Apache log files is the duration of the longest queries, I am curious about these fields and how to translate the corresponding integer values, if they have meaning.
asked 22 Mar '12, 17:50
They mean just how far into the event that Splunk thinks (usually correct) that your timestamp goes.
timestartpos (at which byte the timestamp starts) timeendpos (at which bye into the event the timestamp ends)
If you are experiencing timestamping issues, you should look into how you can alter this behaviour through props.conf settings for your sourcetype;
Hope this helps,
answered 22 Mar '12, 18:47