I have json data coming in that contains a 13 digit epoch value in eventTime, but %s appears to only support 10 digits (https://docs.splunk.com/Documentation/Splunk/8.2.8/Data/Configuretimestamprecognition?ref=hk)
What i'm trying to do is create a source type that will set _time to the value in eventTime when consumed, but struggling to solve it.
I did try setting TIMESTAMP_FIELDS to eventTime and then TIME_FORMAT to %s, but that did not work.
But, I also manually added a 10 digit epoch and it still did not work, so maybe i'm just chasing the wrong idea.
I also tried 'AUTO' but it did not find it.
Looking to learn! Thank you!
Want to note that I also found this:
And my raw json looks like:
So I also tried
But still getting the orange exclamation mark.