I have a request to log a web response that is JSON formatted. The evet looks like
{"state":"OK","id":"135b","date":"2017-07-14","host":"host1","cluster":"cluster_dev"}
I will modify the JSON to include a timestamp but I need to figure out how to get this into a splunk index. I can easiy write apython script using requests to do a get and then post to HEC but I would prefer to find a canned splunk app that will do this.
For HEC you MUST put your timestamp in your root object and preferably as the first element, preferably as a single value. You can have HEC timestamp with the _indextime
(the time the indexer received the event) but I am not aware of any way to take the date from the event and the time from somewhere else.