<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Do I need to modify props to capture 2 format of logs? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Do-I-need-to-modify-props-to-capture-2-format-of-logs/m-p/644361#M16398</link>
    <description>&lt;P&gt;Sample data:&lt;BR /&gt;i have 2 types of data and below props given, i am seeing internal logs like&lt;BR /&gt;&lt;BR /&gt;ERROR JsonLineBreaker - JSON StramID:13457545565443322455 had parsing error: Unexpected character: 'a' - data_source........&lt;BR /&gt;&lt;BR /&gt;Do i need to modify props to capture 2 format of logs??&lt;BR /&gt;&lt;BR /&gt;props:&lt;BR /&gt;[sourcetype]&lt;BR /&gt;INDEXED_EXTRACTIONS=json&lt;BR /&gt;KV_MODE=none&lt;BR /&gt;SHOULD_LINEMERGE=true&lt;BR /&gt;TIMESTAMP_FIELDS=timestamp&lt;BR /&gt;LINE_BREAKER=([\r\n]+)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{[-]
UserID: Null
host: apl-45678
level: medium
message: cliendid: null, secondaryClientid: null, userid: unknown, respinsetime:1.34455
timestamp: 2022-01-22T21:23:44.897Z
}&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{"timestamp": "2022-01-22T21:23:44.897Z", "level":"applevel", "host":"apl-12345", "userid": "NA", "message": apl-12345-20144 - unknown - GET - / - REQ-NAMES - {"accept": "text/plain, application/json:*************************************************************************, "host:""apl-12345", "connection":"unknown"}"}&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{[-]
UserID: Null
host: apl-45678
level: medium
message: cliendid: null, secondaryClientid: null, userid: unknown, respinsetime:1.34455
timestamp: 2022-01-22T21:23:44.897Z
}&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{"timestamp": "2022-01-22T21:23:44.897Z", "level":"applevel", "host":"apl-12345", "userid": "NA",
 "message": apl-12345-20144 - unknown - GET - / - REQ-NAMES - {"accept": "text/plain, application/json:*************************************************************************, "host:""apl-12345", "connection":"unknown"}"}&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 May 2023 14:17:02 GMT</pubDate>
    <dc:creator>mahesh27</dc:creator>
    <dc:date>2023-05-24T14:17:02Z</dc:date>
    <item>
      <title>Do I need to modify props to capture 2 format of logs?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Do-I-need-to-modify-props-to-capture-2-format-of-logs/m-p/644361#M16398</link>
      <description>&lt;P&gt;Sample data:&lt;BR /&gt;i have 2 types of data and below props given, i am seeing internal logs like&lt;BR /&gt;&lt;BR /&gt;ERROR JsonLineBreaker - JSON StramID:13457545565443322455 had parsing error: Unexpected character: 'a' - data_source........&lt;BR /&gt;&lt;BR /&gt;Do i need to modify props to capture 2 format of logs??&lt;BR /&gt;&lt;BR /&gt;props:&lt;BR /&gt;[sourcetype]&lt;BR /&gt;INDEXED_EXTRACTIONS=json&lt;BR /&gt;KV_MODE=none&lt;BR /&gt;SHOULD_LINEMERGE=true&lt;BR /&gt;TIMESTAMP_FIELDS=timestamp&lt;BR /&gt;LINE_BREAKER=([\r\n]+)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{[-]
UserID: Null
host: apl-45678
level: medium
message: cliendid: null, secondaryClientid: null, userid: unknown, respinsetime:1.34455
timestamp: 2022-01-22T21:23:44.897Z
}&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{"timestamp": "2022-01-22T21:23:44.897Z", "level":"applevel", "host":"apl-12345", "userid": "NA", "message": apl-12345-20144 - unknown - GET - / - REQ-NAMES - {"accept": "text/plain, application/json:*************************************************************************, "host:""apl-12345", "connection":"unknown"}"}&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{[-]
UserID: Null
host: apl-45678
level: medium
message: cliendid: null, secondaryClientid: null, userid: unknown, respinsetime:1.34455
timestamp: 2022-01-22T21:23:44.897Z
}&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{"timestamp": "2022-01-22T21:23:44.897Z", "level":"applevel", "host":"apl-12345", "userid": "NA",
 "message": apl-12345-20144 - unknown - GET - / - REQ-NAMES - {"accept": "text/plain, application/json:*************************************************************************, "host:""apl-12345", "connection":"unknown"}"}&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 14:17:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Do-I-need-to-modify-props-to-capture-2-format-of-logs/m-p/644361#M16398</guid>
      <dc:creator>mahesh27</dc:creator>
      <dc:date>2023-05-24T14:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: props for sample data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Do-I-need-to-modify-props-to-capture-2-format-of-logs/m-p/644367#M16399</link>
      <description>&lt;P&gt;You say you have two types of data, but the example look very similar to me.&amp;nbsp; In general, yes, two types of data call for 2 set of props, but I believe that is not the case here.&lt;/P&gt;&lt;P&gt;In this case, I believe the problem is the data is not well-formed JSON so Splunk cannot parse it.&amp;nbsp; Paste the events into jsonlint.com to see what I mean.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 00:08:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Do-I-need-to-modify-props-to-capture-2-format-of-logs/m-p/644367#M16399</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-05-24T00:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: props for sample data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Do-I-need-to-modify-props-to-capture-2-format-of-logs/m-p/644369#M16400</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;, actually i have only json logs before, but now logs with timestamp added.&lt;BR /&gt;so i need props to fetch this other logs as well to avoid json parsing issues.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 00:56:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Do-I-need-to-modify-props-to-capture-2-format-of-logs/m-p/644369#M16400</guid>
      <dc:creator>mahesh27</dc:creator>
      <dc:date>2023-05-24T00:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: props for sample data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Do-I-need-to-modify-props-to-capture-2-format-of-logs/m-p/644371#M16401</link>
      <description>&lt;P&gt;If the pasted JSON is correct then this is badly formatted JSON&lt;/P&gt;&lt;PRE&gt;"host:""apl-12345"&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 01:13:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Do-I-need-to-modify-props-to-capture-2-format-of-logs/m-p/644371#M16401</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-05-24T01:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: props for sample data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Do-I-need-to-modify-props-to-capture-2-format-of-logs/m-p/644373#M16402</link>
      <description>&lt;P&gt;ok will try to change it, but can you please confirm the props i am using is correct??&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 01:24:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Do-I-need-to-modify-props-to-capture-2-format-of-logs/m-p/644373#M16402</guid>
      <dc:creator>mahesh27</dc:creator>
      <dc:date>2023-05-24T01:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: props for sample data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Do-I-need-to-modify-props-to-capture-2-format-of-logs/m-p/644375#M16403</link>
      <description>&lt;P&gt;If it is valid JSON and you want to use INDEXED_EXTRACTIONS then this is all that is needed.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[sourcetype]
INDEXED_EXTRACTIONS=json&lt;/LI-CODE&gt;&lt;P&gt;Note the implications of using this setting though.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.4/Admin/Propsconf#Structured_Data_Header_Extraction_and_configuration" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.4/Admin/Propsconf#Structured_Data_Header_Extraction_and_configuration&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 01:52:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Do-I-need-to-modify-props-to-capture-2-format-of-logs/m-p/644375#M16403</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-05-24T01:52:31Z</dc:date>
    </item>
  </channel>
</rss>

