--- IMPORTANT EDIT --- After I accepted this solution, user @PickleRick suggested a way better one, so I am reporting it here for future use: The /event endpoint gives you more flexibility than /raw so I'd advise to use /event anyway. But in order for HEC input _not_ to skip the timestamp recognition (which it does by default - it either gets the timestamp from the field pushed with (not in!) an event or assigns current timestamp), you must add the ?auto_extract_timestamp=true parameter to the url. Like https://your_indexer:8088/services/collector/event?auto_extract_timestamp=true Here below my original answer: Hi @gcusello I tried this too but no luck. Eventually I solved my problem by changing the HEC endpoint. I was sending data to "/services/collector/event" endpoint. I changed to "/services/collector/raw" and time was indexed correctly with only the TIME_FORMAT property. Thank you for your help anyway!
... View more