<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to write  props for JSON logs? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-write-props-for-JSON-logs/m-p/610872#M13731</link>
    <description>&lt;P&gt;Below is the sample log:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;{[-]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; context: default&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;level: INFO&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;logger: logginfdata.pre-request.util&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; mdc: { [+]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;}&lt;/P&gt;
&lt;P&gt;message:&amp;nbsp; this is a json request&lt;/P&gt;
&lt;P&gt;[evenId=76546787678888899999]]&lt;/P&gt;
&lt;P&gt;thread: RealtimeExecutor-1999&lt;/P&gt;
&lt;P&gt;timestamp: 2022-03-23 15:44:41.965&lt;/P&gt;
&lt;P&gt;}&lt;/P&gt;
&lt;P&gt;may i know how can write props for this kind of logs.&lt;/P&gt;</description>
    <pubDate>Thu, 25 Aug 2022 20:11:51 GMT</pubDate>
    <dc:creator>Vani_26</dc:creator>
    <dc:date>2022-08-25T20:11:51Z</dc:date>
    <item>
      <title>How to write  props for JSON logs?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-write-props-for-JSON-logs/m-p/610872#M13731</link>
      <description>&lt;P&gt;Below is the sample log:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;{[-]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; context: default&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;level: INFO&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;logger: logginfdata.pre-request.util&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; mdc: { [+]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;}&lt;/P&gt;
&lt;P&gt;message:&amp;nbsp; this is a json request&lt;/P&gt;
&lt;P&gt;[evenId=76546787678888899999]]&lt;/P&gt;
&lt;P&gt;thread: RealtimeExecutor-1999&lt;/P&gt;
&lt;P&gt;timestamp: 2022-03-23 15:44:41.965&lt;/P&gt;
&lt;P&gt;}&lt;/P&gt;
&lt;P&gt;may i know how can write props for this kind of logs.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 20:11:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-write-props-for-JSON-logs/m-p/610872#M13731</guid>
      <dc:creator>Vani_26</dc:creator>
      <dc:date>2022-08-25T20:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to write  props for JSON logs?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-write-props-for-JSON-logs/m-p/610904#M13735</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248147"&gt;@Vani_26&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;Can you please share a valid JSON sample event? Just copy _raw and mask data with sample values. Now paste it into the code block.&amp;nbsp; Find this (&lt;STRONG&gt;&amp;lt;/&amp;gt;&lt;/STRONG&gt;) tool in the toolbar for the code block popup. This will help us to answer you with a proper solution.&lt;/P&gt;&lt;P class="lia-align-left"&gt;KV&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2022 05:50:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-write-props-for-JSON-logs/m-p/610904#M13735</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2022-08-26T05:50:16Z</dc:date>
    </item>
  </channel>
</rss>

