We are using the syslog functionality of the analytics agent to collect data.
The logs may be from the past so the creation timestamp is also in the past.
My problem is that AppD always considers the ingestion date as the "timestamp". We can extract the timestamp from the message with regexp but we are not able to use it for charting.
So when we bulk load logs into AppD we try charting we can use only the "ingestion" timestamp so the chart/widget won't be accurate at all.
Do you know who to work around this? We want to use customer timestamps so that we can create accurate charting.
I just re-up this thread.
Does anyone know how to alter the timestamp when we feed in data into the log analytics?