vectordotdev/vector · error
failed to insert timestamp
Error message
failed to insert timestamp
What it means
When input test events carry a millisecond timestamp, the input driver normalizes it into the event's 'timestamp' field via log.parse_path_and_insert. Inserting into an event's log map is infallible for valid paths, so failure triggers this expect. It guards against the internal representation changing or the path lookup behaving unexpectedly.
Solutions
- Re-run with the underlying Err surfaced (replace expect with unwrap_or_else printing the error) to identify which path/value failed.
- After upgrading vector-core event types, update the input driver to use the new insertion API.
- Verify test event fixtures contain a valid Value::Timestamp-compatible ts (DateTime::from_timestamp_millis already validated above).
Defensive patterns
Strategy: validation
Validate before calling
assert!(matches!(ts, Value::Timestamp(_)) || input_ts_millis.is_some(), "input event timestamp must be a valid datetime");
Try / catch
log.parse_path_and_insert("timestamp", ts)
.unwrap_or_else(|e| panic!("failed to insert timestamp: {e}")); Prevention
- Keep input fixtures using millisecond epoch or RFC3339 timestamps.
- Update the input driver after any vector-core event model API change.
- Surface the underlying parse/insert error rather than a bare expect.
When it happens
Trigger: spawn_input_driver processing an input event whose 'timestamp' key cannot be parsed/inserted — currently only realistically triggered by changes to the event data model (parse_path_and_insert returning Err) or a corrupted/frozen test event value.
Common situations: Modifying the event/log value internals in vector-core so the fixed "timestamp" path no longer inserts cleanly; feeding test events with odd value types that a data-model change rejects.
Related errors
- a sink must always have an external resource
- a source must always have an external resource
- breaking fragment ' ' has an invalid anchor ' '. Add ` }`…
- {}
- component name must be non-empty
AI-assisted analysis of vectordotdev/vector@bdb87aeaa4 (2026-09-16).
Data as JSON: /api/errors/41dbcde880efab18.
Report an issue: GitHub.
Appendix: source
Thrown at src/components/validation/runner/mod.rs:631
// Convert unix timestamp in input events to the Datetime string.
// This is necessary when a source expects the incoming event to have a
// unix timestamp but we convert it into a datetime string in the source.
// For example, the `datadog_agent` source. This only takes effect when
// the test case YAML file defining the event, constructs it with the log
// builder variant, and specifies an integer in milliseconds for the timestamp.
if component_type == ComponentType::Source
&& let Event::Log(ref mut log) = event
&& let Some(ts) = log.remove_timestamp()
{
let ts = match ts.as_integer() {
Some(ts) => chrono::DateTime::from_timestamp_millis(ts)
.unwrap_or_else(|| panic!("invalid timestamp in input test event {ts}"))
.into(),
None => ts,
};
log.parse_path_and_insert("timestamp", ts)
.expect("failed to insert timestamp");
}
// This particular metric is tricky because a component can run the
// EstimatedJsonSizeOf calculation on a single event or an array of
// events. If it's an array of events, the size calculation includes
// the size of bracket ('[', ']') characters... But we have no way
// of knowing which case it will be. Indeed, there are even components
// where BOTH scenarios are possible, depending on how the component
// is configured.
// This is handled in the component spec validator code where we compare
// the actual to the expected.
input_runner_metrics.sent_event_bytes_total +=
event.estimated_json_encoded_size_of().get() as u64;
}
}
info!("Input driver sent all events.");
})
}View on GitHub (pinned to bdb87aeaa4)