<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Data is not getting parsed on HEC in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-getting-parsed-on-HEC/m-p/571649#M101224</link>
    <description>&lt;P&gt;I have props.conf&lt;/P&gt;&lt;P&gt;[source::tcp:7660]&lt;BR /&gt;TRUNCATE=10000000&lt;BR /&gt;LINE_BREAKER = {\"time&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;category = Custom&lt;BR /&gt;pulldown_type = true&lt;BR /&gt;KV_MODE = json&lt;BR /&gt;#TZ = America/Chicago&lt;BR /&gt;TZ=UTC&lt;BR /&gt;=====================================&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see some of events are not parsed in json format&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Oct 2021 12:53:09 GMT</pubDate>
    <dc:creator>rahulg</dc:creator>
    <dc:date>2021-10-20T12:53:09Z</dc:date>
    <item>
      <title>Data is not getting parsed on HEC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-getting-parsed-on-HEC/m-p/571649#M101224</link>
      <description>&lt;P&gt;I have props.conf&lt;/P&gt;&lt;P&gt;[source::tcp:7660]&lt;BR /&gt;TRUNCATE=10000000&lt;BR /&gt;LINE_BREAKER = {\"time&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;category = Custom&lt;BR /&gt;pulldown_type = true&lt;BR /&gt;KV_MODE = json&lt;BR /&gt;#TZ = America/Chicago&lt;BR /&gt;TZ=UTC&lt;BR /&gt;=====================================&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see some of events are not parsed in json format&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 12:53:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-getting-parsed-on-HEC/m-p/571649#M101224</guid>
      <dc:creator>rahulg</dc:creator>
      <dc:date>2021-10-20T12:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: Data is not getting parsed on HEC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-getting-parsed-on-HEC/m-p/571662#M101226</link>
      <description>&lt;P&gt;Is the HEC configured on Heavy forwarder/indexer? Check if events which are not parsed as json is in pure JSON format. Did you setup KV_MODE=JSON on your search head(s)?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 14:01:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-getting-parsed-on-HEC/m-p/571662#M101226</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2021-10-20T14:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: Data is not getting parsed on HEC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-getting-parsed-on-HEC/m-p/571663#M101227</link>
      <description>&lt;P&gt;Which endpoint are you send your events to?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 14:12:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-getting-parsed-on-HEC/m-p/571663#M101227</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-20T14:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: Data is not getting parsed on HEC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-getting-parsed-on-HEC/m-p/572276#M101282</link>
      <description>&lt;P&gt;&lt;SPAN&gt;HEC configured on Heavy forwarder and i dont have KV_MODE=JSON on search head(s) will that help?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 13:55:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-getting-parsed-on-HEC/m-p/572276#M101282</guid>
      <dc:creator>rahulg</dc:creator>
      <dc:date>2021-10-25T13:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: Data is not getting parsed on HEC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-getting-parsed-on-HEC/m-p/572282#M101284</link>
      <description>&lt;P&gt;Firstly, I think you don't need line breaking settings since you supply whole single events to the /event endpoint.&lt;/P&gt;&lt;P&gt;Secondly - KV_MODE is a search-time setting so yes, you need it on search-heads, not on indexers/HF's&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 14:11:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-getting-parsed-on-HEC/m-p/572282#M101284</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-25T14:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: Data is not getting parsed on HEC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-getting-parsed-on-HEC/m-p/573264#M101410</link>
      <description>&lt;P&gt;Here is sample events which is working fine&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;{ [-]&lt;BR /&gt;command: C:\Windows\System32\sdfhlsdhjfjsnsdf&lt;BR /&gt;company_1: Microsoft Corporation&lt;BR /&gt;company_2: Microsoft Corporation&lt;BR /&gt;connection_count: 0&lt;BR /&gt;created: Mon Nov 1 07:52:10 2021&lt;BR /&gt;created_1: Sun Jun 6 1&lt;BR /&gt;created_2: Sun Jun 6 14:52:03.721 2021&lt;BR /&gt;desc_1: Runtime Broker&lt;BR /&gt;desc_2: Host Process for Windows Services&lt;BR /&gt;exists_1: yes&lt;BR /&gt;exists_2: yes&lt;BR /&gt;file_1: C:\Windows\System32\kjksnkfhskf&lt;BR /&gt;file_2: C:\Windows\System32\svchost.exe&lt;BR /&gt;firstbytes_1: jhsfkszhkfhnkkllks.ndklfsf&lt;BR /&gt;firstbytes_2: hkdhfkgkdhfgknzdlfgnl.sdflgndlkfgnld&lt;BR /&gt;hostname: nkdnf.ks&lt;BR /&gt;imphash_1: .nsdlkfnlszknflsNLfnzslkdnfksnkfnskfn&lt;BR /&gt;imphash_2: nsdnfknfaksnfdksnflnfknskdfnksnafdks&lt;BR /&gt;legal_copyright_1: © Microsoft Corporation. All rights reserved.&lt;BR /&gt;legal_copyright_2: © Microsoft Corporation. All rights reserved.&lt;BR /&gt;level: Info&lt;BR /&gt;listen_ports:&lt;BR /&gt;md5: nbzkdfnkzshdkfjskJnfkznfksnk&lt;BR /&gt;md5_1: ksndlfn.ksndfknsakf&lt;BR /&gt;md5_2: nKSndkfksdfnksandfknsak&lt;BR /&gt;message: Process info&lt;BR /&gt;module: ProcessCheck&lt;BR /&gt;name: RuntimeBroker.exe&lt;BR /&gt;owner: NM\JOIN4029&lt;BR /&gt;owner_1: NT SERVICE\TrustedInstaller&lt;BR /&gt;owner_2: NT SERVICE\TrustedInstaller&lt;BR /&gt;parent: C:\Windows\System32\svchost.exe&lt;BR /&gt;path: C:\Windows\System32\RuntimeBroker.exe&lt;BR /&gt;pid: 24080&lt;BR /&gt;ppid: 1264&lt;BR /&gt;scanid: S-bszkdbfksnbdfkjs&lt;BR /&gt;sha1_1: kndfnkzdnfkdnakgnkfgnxkdzn&lt;BR /&gt;sha1_2: ndxnfvkznfnkmzfxbvkzdbfvkbzkbxdv&lt;BR /&gt;sha256_1: oiajsosfu094ursjofjlsjdflk&lt;BR /&gt;sha256_2: knsldkflzsdjflkslkf&lt;BR /&gt;size_1: 8679890&lt;BR /&gt;size_2: 567890&lt;BR /&gt;time: 2021-11-01T14:18:26Z&lt;BR /&gt;type_1: EXE&lt;BR /&gt;type_2: EXE&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if it has file_1 and file_2 works fine and if addition file_3 or similar sha256_3&amp;nbsp; or any _etc field ect gets added it doesnt&amp;nbsp; shows ja\son format&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 06:18:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-getting-parsed-on-HEC/m-p/573264#M101410</guid>
      <dc:creator>rahulg</dc:creator>
      <dc:date>2021-11-02T06:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Data is not getting parsed on HEC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-getting-parsed-on-HEC/m-p/573279#M101414</link>
      <description>&lt;P&gt;Check if the fields are present in raw event. Then you'll know if it's a parsing problem or ingestion one.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 09:16:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-is-not-getting-parsed-on-HEC/m-p/573279#M101414</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-02T09:16:50Z</dc:date>
    </item>
  </channel>
</rss>

