Overwride field "_time" in splunk

I have logstash config that send logs to Splunk HEC.
these data contain field that call "time".
Now question is: does it possible to consider "time" as "_time" on logstash config?

FYI: i want to consider this time as _time not the time that splunk receive it.
Any idea?

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.