<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to remove header to have only json element in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/How-to-remove-header-to-have-only-json-element/m-p/565426#M10047</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a log like this :&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;2021-09-01T07:25:12.314Z&lt;/SPAN&gt;&amp;nbsp;id-xxx-xxx-xxx STATE&amp;nbsp;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;{&lt;/STRONG&gt;&lt;/FONT&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Id&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"id-xxx-xxx-xxx&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;timestamp&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;2021-09-01T07:25:12.145Z&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;sourceType&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"my_sourcetype&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;source&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"source_name&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Type&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"my_&lt;/SPAN&gt;&lt;SPAN class="t"&gt;type&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;event&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;{&lt;/FONT&gt;&lt;/STRONG&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;field&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;my_field&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;}&lt;/STRONG&gt;&lt;/FONT&gt;,"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;time&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:169&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;category&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;XXX&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;}&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My props.conf is like that :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[extract_json]&lt;BR /&gt;TRUNCATE = 999999&lt;/P&gt;&lt;P&gt;SHOULD_LINEMERGE=true&lt;BR /&gt;NO_BINARY_CHECK=true&lt;BR /&gt;TIME_PREFIX=timestamp:&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD=10000&lt;BR /&gt;BREAK_ONLY_BEFORE ={$&lt;BR /&gt;MUST_BREAK_AFTER=}$&lt;/P&gt;&lt;P&gt;SEDCMD-remove-header = s/^[0-9T\:Z]*.*\s*{/{/g&lt;/P&gt;&lt;P&gt;My issue is that I need to extract only the json element from my logs but with those parameters from my props I get a bad extraction : the end of my json (&amp;nbsp;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;{&lt;/STRONG&gt;&lt;/FONT&gt;"&lt;SPAN class="t"&gt;field&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;my_field&lt;/SPAN&gt;"&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;}&lt;/FONT&gt;&lt;/STRONG&gt;,"&lt;SPAN class="t"&gt;time&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:169&lt;/SPAN&gt;,"&lt;SPAN class="t"&gt;category&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;XXX&lt;/SPAN&gt;"&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;}&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#000000"&gt; ) goes to an other event line and is not in json.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT color="#000000"&gt;I have children brackets into parent bracket and I think my SEDCMD is not correct.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT color="#000000"&gt;I would have the entire json element in one event.&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT color="#000000"&gt;Can you help me please ?&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT color="#000000"&gt;Thank you !&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Sep 2021 08:00:13 GMT</pubDate>
    <dc:creator>mah</dc:creator>
    <dc:date>2021-09-01T08:00:13Z</dc:date>
    <item>
      <title>How to remove header to have only json element</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-to-remove-header-to-have-only-json-element/m-p/565426#M10047</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a log like this :&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;2021-09-01T07:25:12.314Z&lt;/SPAN&gt;&amp;nbsp;id-xxx-xxx-xxx STATE&amp;nbsp;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;{&lt;/STRONG&gt;&lt;/FONT&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Id&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"id-xxx-xxx-xxx&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;timestamp&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;2021-09-01T07:25:12.145Z&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;sourceType&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"my_sourcetype&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;source&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"source_name&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Type&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"my_&lt;/SPAN&gt;&lt;SPAN class="t"&gt;type&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;event&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;{&lt;/FONT&gt;&lt;/STRONG&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;field&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;my_field&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;}&lt;/STRONG&gt;&lt;/FONT&gt;,"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;time&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:169&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;category&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;XXX&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;}&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My props.conf is like that :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[extract_json]&lt;BR /&gt;TRUNCATE = 999999&lt;/P&gt;&lt;P&gt;SHOULD_LINEMERGE=true&lt;BR /&gt;NO_BINARY_CHECK=true&lt;BR /&gt;TIME_PREFIX=timestamp:&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD=10000&lt;BR /&gt;BREAK_ONLY_BEFORE ={$&lt;BR /&gt;MUST_BREAK_AFTER=}$&lt;/P&gt;&lt;P&gt;SEDCMD-remove-header = s/^[0-9T\:Z]*.*\s*{/{/g&lt;/P&gt;&lt;P&gt;My issue is that I need to extract only the json element from my logs but with those parameters from my props I get a bad extraction : the end of my json (&amp;nbsp;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;{&lt;/STRONG&gt;&lt;/FONT&gt;"&lt;SPAN class="t"&gt;field&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;my_field&lt;/SPAN&gt;"&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;}&lt;/FONT&gt;&lt;/STRONG&gt;,"&lt;SPAN class="t"&gt;time&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:169&lt;/SPAN&gt;,"&lt;SPAN class="t"&gt;category&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;XXX&lt;/SPAN&gt;"&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;}&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#000000"&gt; ) goes to an other event line and is not in json.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT color="#000000"&gt;I have children brackets into parent bracket and I think my SEDCMD is not correct.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT color="#000000"&gt;I would have the entire json element in one event.&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT color="#000000"&gt;Can you help me please ?&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT color="#000000"&gt;Thank you !&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2021 08:00:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-to-remove-header-to-have-only-json-element/m-p/565426#M10047</guid>
      <dc:creator>mah</dc:creator>
      <dc:date>2021-09-01T08:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove header to have only json element</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-to-remove-header-to-have-only-json-element/m-p/565427#M10048</link>
      <description>&lt;P&gt;Try something like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;SEDCMD-remove-header = s/^[0-9T\:Z]*.*?\s*{/{/g&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 01 Sep 2021 08:15:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-to-remove-header-to-have-only-json-element/m-p/565427#M10048</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-09-01T08:15:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove header to have only json element</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-to-remove-header-to-have-only-json-element/m-p/565444#M10049</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems to work&amp;nbsp; great !&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot !&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2021 09:24:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-to-remove-header-to-have-only-json-element/m-p/565444#M10049</guid>
      <dc:creator>mah</dc:creator>
      <dc:date>2021-09-01T09:24:25Z</dc:date>
    </item>
  </channel>
</rss>

