Open allahshukur-ahmadzada opened 1 year ago
I was looking to use eventTime as timestamp for opensearch index pattern but its being null for majority of events makes it useless
same problem for me
I worked around this issue using an ingest pipeline that looks like this:
{
"processors": [
{
"set": {
"field": "@timestamp",
"value": "{{eventTime}}",
"if": "ctx.eventTime != null"
}
},
{
"set": {
"field": "@timestamp",
"value": "{{firstTimestamp}}",
"if": "ctx.firstTimestamp != null"
}
}
]
}
It's not perfect, but at least I can use the Discover view now...
why most of the event logs comes with empty eventTime field? it is a bug?