Dear All,
I am getting data from the Search head in json format. The first field of the event is timestamp and it is in epoch time format("timestamp": 1609414219738696) with 16 digits.
My problem is i need to onboard data with _time value from timestamp field. So in props.conf file of Cluster master i updated as below
TIMESTAMP_FIELDS = timestamp
TIME_FORMAT = %s%6N
But the _time field is not populated properly . And i am getting 2 values in indexed data for timestamp field as below.
Please help me on this