I have log files with file names like:
report-2012-02-25.csv
report-2012-02-26.csv
In those reports only some events have a date field.
How could I force Splunk to use the date extracted from the file name instead of the dates recognized in the events for all of them?
Thank you for that, but found another problem. Time field is needed to be present in the events based on the documentation: