Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Sink Connector time field not moved to splunk time field #17

Open
patspruyt opened this issue Apr 3, 2018 · 0 comments
Open

Sink Connector time field not moved to splunk time field #17

patspruyt opened this issue Apr 3, 2018 · 0 comments

Comments

@patspruyt
Copy link

From the documentation:

The Sink Connector will pull over all of the fields that are in the incoming schema. If there is a timestamp field named date or time it will be converted to a Splunk timestamp and moved to the time field

The "time" field is removed from the event object (as expected) but is not moved to the "splunk time field".

What is the right time format to use (already tried epoc, epoc_milli and ISO) ?

The "host" field is moved as expected.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant