Right now, adding Time fields hard codes to _time, which is fine for Splunk but not so much for other systems.