kafka-connect-splunk icon indicating copy to clipboard operation
kafka-connect-splunk copied to clipboard

Sink Connector time field not moved to splunk time field

Open patspruyt opened this issue 6 years ago • 0 comments

From the documentation:

The Sink Connector will pull over all of the fields that are in the incoming schema. If there is a timestamp field named date or time it will be converted to a Splunk timestamp and moved to the time field

The "time" field is removed from the event object (as expected) but is not moved to the "splunk time field".

What is the right time format to use (already tried epoc, epoc_milli and ISO) ?

The "host" field is moved as expected.

patspruyt avatar Apr 03 '18 14:04 patspruyt