Closed kashyap-splunk closed 2 years ago
@kashyap-splunk Does HEC support nano second yet?
Yes @luckyj5 . I was not sure as I could not find the explicit info in docs. But I tried and I was able to get nanoseconds in the events. An example from recent events:
Yes @luckyj5 . I was not sure as I could not find the explicit info in docs. But I tried and I was able to get nanoseconds in the events. An example from recent events:
@kashyap-splunk Does users have option to control it if they aren't looking for nano second precision?
No, it will be nanosecond precision always if this change is done. It can be made configurable via an additional config param if this seems to potentially cause any issues.
@kashyap-splunk is this in scope and waiting on approval?
Approving this PR as its reviewed and approved by @aryznar-splunk internally. A documentation update (breaking change) would be good to add here. Thanks!
This is to fix an issue, where events with micro/nano second timestamps were not sorted properly due to timestamps getting truncated up to milliseconds.