fluent-plugin-splunk
fluent-plugin-splunk copied to clipboard
enable 'event_key' for non-raw setup.
event_key is currently only supported when in 'raw' mode. It will be beneficial to also have this option in the other mode - usually the event is a json object, and this enables the plugin to send just the log string as the event. When compared to using just 'raw' mode - this method adds various benefits - such as being able to use 'use_fluentd_time'