Replies: 1 comment
-
Unfortunately that field isn't templatable currently. It'd be a bit tricky to make templatable since Splunk expects that parameter as a URL parameter and so requests would need to be partitioned across them. We'd be open to seeing a PR adding this as a feature though. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi,
Currently trying to set the value of
auto_extract_timestamp
which expects a boolean in the Splunk Hec sink based on a boolean value in the event. Eg'{{ .config.logs.auto_extract_timestamp }}'
.This fails validation as the template is parsed and expressed as a string.
validate
fails validation withx invalid type: string "{{ .config.logs.auto_extract_timestamp }}", expected a boolean
So I'm wondering if there any other way I could set this value in the configuration based on the value in the event field?
Thanks
Beta Was this translation helpful? Give feedback.
All reactions