You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The Sink Connector will pull over all of the fields that are in the incoming schema. If there is a timestamp field named date or time it will be converted to a Splunk timestamp and moved to the time field
The "time" field is removed from the event object (as expected) but is not moved to the "splunk time field".
What is the right time format to use (already tried epoc, epoc_milli and ISO) ?
The "host" field is moved as expected.
The text was updated successfully, but these errors were encountered:
From the documentation:
The "time" field is removed from the event object (as expected) but is not moved to the "splunk time field".
What is the right time format to use (already tried epoc, epoc_milli and ISO) ?
The "host" field is moved as expected.
The text was updated successfully, but these errors were encountered: