Currently sumo logic is only correctly capturing the timestamps from some of the logs provided. These logs are all from the past, and so were uploaded to sumo logic at once. The formats are different for some of the logs, and it seems the ability of sumo logic to parse the timestamps is related to that, but the most straightforward timestamps to parse aren't getting parsed accurately, and it seems like maybe the receipt time is being used instead? Receipt time is not checked in this query.
Please sign in to leave a comment.