vectordotdev/vector · error

failed to insert timestamp

Error message

failed to insert timestamp

What it means

When input test events carry a millisecond timestamp, the input driver normalizes it into the event's 'timestamp' field via log.parse_path_and_insert. Inserting into an event's log map is infallible for valid paths, so failure triggers this expect. It guards against the internal representation changing or the path lookup behaving unexpectedly.

Solutions

  1. Re-run with the underlying Err surfaced (replace expect with unwrap_or_else printing the error) to identify which path/value failed.
  2. After upgrading vector-core event types, update the input driver to use the new insertion API.
  3. Verify test event fixtures contain a valid Value::Timestamp-compatible ts (DateTime::from_timestamp_millis already validated above).
Defensive patterns

Strategy: validation

Validate before calling

assert!(matches!(ts, Value::Timestamp(_)) || input_ts_millis.is_some(), "input event timestamp must be a valid datetime");

Try / catch

log.parse_path_and_insert("timestamp", ts)
    .unwrap_or_else(|e| panic!("failed to insert timestamp: {e}"));

Prevention

When it happens

Trigger: spawn_input_driver processing an input event whose 'timestamp' key cannot be parsed/inserted — currently only realistically triggered by changes to the event data model (parse_path_and_insert returning Err) or a corrupted/frozen test event value.

Common situations: Modifying the event/log value internals in vector-core so the fixed "timestamp" path no longer inserts cleanly; feeding test events with odd value types that a data-model change rejects.

Related errors


AI-assisted analysis of vectordotdev/vector@bdb87aeaa4 (2026-09-16). Data as JSON: /api/errors/41dbcde880efab18. Report an issue: GitHub.

Appendix: source

Thrown at src/components/validation/runner/mod.rs:631

                // Convert unix timestamp in input events to the Datetime string.
                // This is necessary when a source expects the incoming event to have a
                // unix timestamp but we convert it into a datetime string in the source.
                // For example, the `datadog_agent` source. This only takes effect when
                // the test case YAML file defining the event, constructs it with the log
                // builder variant, and specifies an integer in milliseconds for the timestamp.
                if component_type == ComponentType::Source
                    && let Event::Log(ref mut log) = event
                    && let Some(ts) = log.remove_timestamp()
                {
                    let ts = match ts.as_integer() {
                        Some(ts) => chrono::DateTime::from_timestamp_millis(ts)
                            .unwrap_or_else(|| panic!("invalid timestamp in input test event {ts}"))
                            .into(),
                        None => ts,
                    };
                    log.parse_path_and_insert("timestamp", ts)
                        .expect("failed to insert timestamp");
                }

                // This particular metric is tricky because a component can run the
                // EstimatedJsonSizeOf calculation on a single event or an array of
                // events. If it's an array of events, the size calculation includes
                // the size of bracket ('[', ']') characters... But we have no way
                // of knowing which case it will be. Indeed, there are even components
                // where BOTH scenarios are possible, depending on how the component
                // is configured.
                // This is handled in the component spec validator code where we compare
                // the actual to the expected.
                input_runner_metrics.sent_event_bytes_total +=
                    event.estimated_json_encoded_size_of().get() as u64;
            }
        }
        info!("Input driver sent all events.");
    })
}

View on GitHub (pinned to bdb87aeaa4)