Hi @livehybrid , I wanted this while indexing data. I don't see the value of the timestamp is overriden with the actual value it has(epoch), Addition to it, i see the value none returning in the ti...
See more...
Hi @livehybrid , I wanted this while indexing data. I don't see the value of the timestamp is overriden with the actual value it has(epoch), Addition to it, i see the value none returning in the timestamp values. I wanted the event to be shown something like this in the splunk results. raw_event: before indexing. {"level":"warn","service":"resource-sweeper","timestamp":1744382735963,"message":"1 nodes are not allocated"} {"level":"warn","service":"resource-sweeper","timestamp":1744390525975,"message":"1 nodes are not allocated"} {"level":"warn","service":"resource-sweeper","timestamp":1744390538019,"message":"2 nodes are not allocated"} {"level":"warn","service":"resource-sweeper","timestamp":1744390555970,"message":"1 nodes are not allocated"} I wanted the events to be shown in splunk this way: {"level":"warn","service":"resource-sweeper","timestamp":1744382735963,"message":"1 nodes are not allocated"} {"level":"warn","service":"resource-sweeper","timestamp":1744390525975,"message":"1 nodes are not allocated"} {"level":"warn","service":"resource-sweeper","timestamp":1744390538019,"message":"2 nodes are not allocated"} {"level":"warn","service":"resource-sweeper","timestamp":1744390555970,"message":"1 nodes are not allocated"} {"level":"warn","service":"resource-sweeper","timestamp”:04/16/2025 16:55:23.650,”message":"1 nodes are not allocated"} {"level":"warn","service":"resource-sweeper","timestamp":04/16/2025 16:55:25.975,"message":"1 nodes are not allocated"} {"level":"warn","service":"resource-sweeper","timestamp":04/16/2025 16:55:38.019,"message":"2 nodes are not allocated"} {"level":"warn","service":"resource-sweeper","timestamp":04/16/2025 16:55:55.970,”message":"1 nodes are not allocated"} The values of the timestamp should be the above one's.