<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic jsonlinebreaker processing a valid json file in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/jsonlinebreaker-processing-a-valid-json-file/m-p/574552#M101563</link>
    <description>&lt;P&gt;I am forwarding some json files from a splunk forwarder on linux, example file below:&lt;/P&gt;&lt;P&gt;{&lt;BR /&gt;"dateTime" : "04/11/2021 08:22:30",&lt;BR /&gt;"functionName" : "ZAUTOPSRALL",&lt;BR /&gt;"userId" : "sanchez",&lt;BR /&gt;"issueCategory" : "PSR",&lt;BR /&gt;"issueType" : "HDRUNKNOWN",&lt;BR /&gt;"issueSummary" : "PSR File Processing â\u0080\u0093 Cannot match to original file",&lt;BR /&gt;"issueDescription" : "The received PSR file &amp;amp;quot;PSR_CBD174.PAIN001_DTLRJCT3.xml&amp;amp;quot; refers to an unknown original file.\n\nPSR file\nName: PSR_CBD174.PAIN001_DTLRJCT3.xml\nCreated: 2021-10-08T12:09:43+01:00\nMessage ID: LBG/0000000027834/003\n\nReference to original file\nMessage ID: MSGID/PAIN001/20210913T100930/1\nStatus: RJCT\nControl sum: 38965.82\nNumber of transactions: 86",&lt;BR /&gt;"exceptionType" : null,&lt;BR /&gt;"notificationId" : null,&lt;BR /&gt;"timeStamp" : 1636014150661056&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;Its not being indexed, i found the following errors for this fle in the splunkd.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran the json through a json checker and it was valid so not sure why splunk is complaining.&amp;nbsp; Any help would be much apreciated.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;11-05-2021 15:48:57.625 +0000 ERROR JsonLineBreaker [10224113 structuredparsing] - JSON StreamId:14224088848725967690 had parsing error:Unexpected character while parsing backslash escape: 'x' - data_source="/sanchez/instances/beta/log/splunk/splunk_1636014150661056_19399032.json", data_host="pbasalsldw002", data_sourcetype="_json"&lt;/P&gt;&lt;P&gt;11-05-2021 15:48:57.625 +0000 ERROR JsonLineBreaker [10224113 structuredparsing] - JSON StreamId:14224088848725967690 had parsing error:Unexpected character: ':' - data_source="/sanchez/instances/beta/log/splunk/splunk_1636014150661056_19399032.json", data_host="pbasalsldw002", data_sourcetype="_json"&lt;/P&gt;&lt;P&gt;11-05-2021 15:48:57.625 +0000 ERROR JsonLineBreaker [10224113 structuredparsing] - JSON StreamId:14224088848725967690 had parsing error:Unexpected character: ':' - data_source="/sanchez/instances/beta/log/splunk/splunk_1636014150661056_19399032.json", data_host="pbasalsldw002", data_sourcetype="_json"&lt;/P&gt;&lt;P&gt;11-05-2021 15:48:57.625 +0000 ERROR JsonLineBreaker [10224113 structuredparsing] - JSON StreamId:14224088848725967690 had parsing error:Unexpected character: ':' - data_source="/sanchez/instances/beta/log/splunk/splunk_1636014150661056_19399032.json", data_host="pbasalsldw002", data_sourcetype="_json"&lt;/P&gt;&lt;P&gt;11-05-2021 15:48:57.625 +0000 ERROR JsonLineBreaker [10224113 structuredparsing] - JSON StreamId:14224088848725967690 had parsing error:Unexpected character in string: '\0A' - data_source="/sanchez/instances/beta/log/splunk/splunk_1636014150661056_19399032.json", data_host="pbasalsldw002", data_sourcetype="_json"&lt;/P&gt;</description>
    <pubDate>Thu, 11 Nov 2021 12:10:04 GMT</pubDate>
    <dc:creator>kulrajatwal</dc:creator>
    <dc:date>2021-11-11T12:10:04Z</dc:date>
    <item>
      <title>jsonlinebreaker processing a valid json file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/jsonlinebreaker-processing-a-valid-json-file/m-p/574552#M101563</link>
      <description>&lt;P&gt;I am forwarding some json files from a splunk forwarder on linux, example file below:&lt;/P&gt;&lt;P&gt;{&lt;BR /&gt;"dateTime" : "04/11/2021 08:22:30",&lt;BR /&gt;"functionName" : "ZAUTOPSRALL",&lt;BR /&gt;"userId" : "sanchez",&lt;BR /&gt;"issueCategory" : "PSR",&lt;BR /&gt;"issueType" : "HDRUNKNOWN",&lt;BR /&gt;"issueSummary" : "PSR File Processing â\u0080\u0093 Cannot match to original file",&lt;BR /&gt;"issueDescription" : "The received PSR file &amp;amp;quot;PSR_CBD174.PAIN001_DTLRJCT3.xml&amp;amp;quot; refers to an unknown original file.\n\nPSR file\nName: PSR_CBD174.PAIN001_DTLRJCT3.xml\nCreated: 2021-10-08T12:09:43+01:00\nMessage ID: LBG/0000000027834/003\n\nReference to original file\nMessage ID: MSGID/PAIN001/20210913T100930/1\nStatus: RJCT\nControl sum: 38965.82\nNumber of transactions: 86",&lt;BR /&gt;"exceptionType" : null,&lt;BR /&gt;"notificationId" : null,&lt;BR /&gt;"timeStamp" : 1636014150661056&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;Its not being indexed, i found the following errors for this fle in the splunkd.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran the json through a json checker and it was valid so not sure why splunk is complaining.&amp;nbsp; Any help would be much apreciated.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;11-05-2021 15:48:57.625 +0000 ERROR JsonLineBreaker [10224113 structuredparsing] - JSON StreamId:14224088848725967690 had parsing error:Unexpected character while parsing backslash escape: 'x' - data_source="/sanchez/instances/beta/log/splunk/splunk_1636014150661056_19399032.json", data_host="pbasalsldw002", data_sourcetype="_json"&lt;/P&gt;&lt;P&gt;11-05-2021 15:48:57.625 +0000 ERROR JsonLineBreaker [10224113 structuredparsing] - JSON StreamId:14224088848725967690 had parsing error:Unexpected character: ':' - data_source="/sanchez/instances/beta/log/splunk/splunk_1636014150661056_19399032.json", data_host="pbasalsldw002", data_sourcetype="_json"&lt;/P&gt;&lt;P&gt;11-05-2021 15:48:57.625 +0000 ERROR JsonLineBreaker [10224113 structuredparsing] - JSON StreamId:14224088848725967690 had parsing error:Unexpected character: ':' - data_source="/sanchez/instances/beta/log/splunk/splunk_1636014150661056_19399032.json", data_host="pbasalsldw002", data_sourcetype="_json"&lt;/P&gt;&lt;P&gt;11-05-2021 15:48:57.625 +0000 ERROR JsonLineBreaker [10224113 structuredparsing] - JSON StreamId:14224088848725967690 had parsing error:Unexpected character: ':' - data_source="/sanchez/instances/beta/log/splunk/splunk_1636014150661056_19399032.json", data_host="pbasalsldw002", data_sourcetype="_json"&lt;/P&gt;&lt;P&gt;11-05-2021 15:48:57.625 +0000 ERROR JsonLineBreaker [10224113 structuredparsing] - JSON StreamId:14224088848725967690 had parsing error:Unexpected character in string: '\0A' - data_source="/sanchez/instances/beta/log/splunk/splunk_1636014150661056_19399032.json", data_host="pbasalsldw002", data_sourcetype="_json"&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 12:10:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/jsonlinebreaker-processing-a-valid-json-file/m-p/574552#M101563</guid>
      <dc:creator>kulrajatwal</dc:creator>
      <dc:date>2021-11-11T12:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: jsonlinebreaker processing a valid json file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/jsonlinebreaker-processing-a-valid-json-file/m-p/574944#M101612</link>
      <description>&lt;P&gt;I found by running json through&lt;/P&gt;&lt;P&gt;cat &amp;lt;json file&amp;gt; | od -A n -t x1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could see all the hex chars relating to the splunk errors and fix the json to a format splunk accepts&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 15:31:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/jsonlinebreaker-processing-a-valid-json-file/m-p/574944#M101612</guid>
      <dc:creator>kulrajatwal</dc:creator>
      <dc:date>2021-11-15T15:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: jsonlinebreaker processing a valid json file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/jsonlinebreaker-processing-a-valid-json-file/m-p/702663#M116216</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/126400"&gt;@kulrajatwal&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to check in hex chars?&lt;/P&gt;&lt;P&gt;I have the same issues in my splunk, So I got the raw data file and process your command to it.&lt;/P&gt;&lt;P&gt;But I don't know how to check the invalid chars in my raw data.&lt;/P&gt;&lt;P&gt;Could you explain in detail? What is the splunk's accepted format? and how to fix in my json?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 06:04:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/jsonlinebreaker-processing-a-valid-json-file/m-p/702663#M116216</guid>
      <dc:creator>WonjinKim</dc:creator>
      <dc:date>2024-10-24T06:04:57Z</dc:date>
    </item>
  </channel>
</rss>

