Does anyone know if the _indextime
field is assigned during the parsing phase or when the event is written into the index? I'm assuming that, as a meta field, it is actually created at parsing time, but I'm looking for confirmation.
Specifically, in the case of a UF -> intermediate heavy forwarder -> indexer, I'd like to know if event lag is occurring on the indexer. But I can't determine that if indextime is set during the parsing phase.
_indextime is determined in the indexing pipeline processor just before an event is written to disk, so there is little to no chance for lag introduced at that processing phase.
_indextime is determined in the indexing pipeline processor just before an event is written to disk, so there is little to no chance for lag introduced at that processing phase.