<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to avoid influence of equal sign in text string when Splunk HEC parses JSON? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-influence-of-equal-sign-in-text-string-when-Splunk/m-p/607988#M105519</link>
    <description>&lt;P&gt;I was tring to ingest data into Splunk via HEC. One field of my data is:&lt;/P&gt;
&lt;P&gt;myKey1 = " This is my Application message log, myKey2=myValue2 in the text."&amp;nbsp; There is a Key=VALUE enclosed in the value of Field_name.&lt;/P&gt;
&lt;P&gt;Splunk will parse the data into two key:&lt;/P&gt;
&lt;P&gt;myKey1 = " This is my Application message log, KEY=VALUE in the text."&amp;nbsp;&lt;/P&gt;
&lt;P&gt;myKey2=myValue2&lt;/P&gt;
&lt;P&gt;myKey2=myValue2 is part of the myKey1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't want it. What I can do to avoid the influence of an equal sign in the text string?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Aug 2022 14:38:04 GMT</pubDate>
    <dc:creator>cdp_fap</dc:creator>
    <dc:date>2022-08-03T14:38:04Z</dc:date>
    <item>
      <title>How to avoid influence of equal sign in text string when Splunk HEC parses JSON?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-influence-of-equal-sign-in-text-string-when-Splunk/m-p/607988#M105519</link>
      <description>&lt;P&gt;I was tring to ingest data into Splunk via HEC. One field of my data is:&lt;/P&gt;
&lt;P&gt;myKey1 = " This is my Application message log, myKey2=myValue2 in the text."&amp;nbsp; There is a Key=VALUE enclosed in the value of Field_name.&lt;/P&gt;
&lt;P&gt;Splunk will parse the data into two key:&lt;/P&gt;
&lt;P&gt;myKey1 = " This is my Application message log, KEY=VALUE in the text."&amp;nbsp;&lt;/P&gt;
&lt;P&gt;myKey2=myValue2&lt;/P&gt;
&lt;P&gt;myKey2=myValue2 is part of the myKey1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't want it. What I can do to avoid the influence of an equal sign in the text string?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 14:38:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-influence-of-equal-sign-in-text-string-when-Splunk/m-p/607988#M105519</guid>
      <dc:creator>cdp_fap</dc:creator>
      <dc:date>2022-08-03T14:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk HEC parse json unexcepted when equal sign in string</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-influence-of-equal-sign-in-text-string-when-Splunk/m-p/607997#M105520</link>
      <description>&lt;P&gt;Question: Have you attempted the same search SPL in 'Fast Mode' vs 'Smart or Verbose Modes'.&amp;nbsp; &amp;nbsp;Part of the power of Splunk is how much it tries to help you.&amp;nbsp; In this case the Search Head may be trying to auto detect fields for the user.&lt;/P&gt;&lt;P&gt;You could if required reduce the length of the event which field discovery will attempt, I believe default is ~10,000 characters to something much lower.&amp;nbsp; However, I think that would overall be a poorer experience for your user base.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 05:53:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-influence-of-equal-sign-in-text-string-when-Splunk/m-p/607997#M105520</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2022-08-03T05:53:52Z</dc:date>
    </item>
  </channel>
</rss>

