<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why the error while ingesting a JSON file &amp;quot;Jsonlinebreaker parsing error unexpected character /&amp;quot;? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-the-error-while-ingesting-a-JSON-file-quot-Jsonlinebreaker/m-p/626299#M107601</link>
    <description>&lt;P&gt;I'm trying to ingest a json file and got the following error:&lt;/P&gt;
&lt;P&gt;splunkd.log:01-07-2023 00:42:51.375 +0100 ERROR JsonLineBreaker [36024 parsing] - JSON StreamId:229865635822760533 had parsing error:Unexpected character: '/' - data_source="/opt/rfcanalyzer/var/log/housekeeping/dailyupdates.log", data_host="vrfcanalyzer.rfcanalyzer.net", data_sourcetype="_json"&lt;/P&gt;
&lt;P&gt;Splunk complains about the following jsons:&lt;/P&gt;
&lt;P&gt;{"tstamp": "2023-01-07 16:23:12", "severity": "INFO", "process": "dailyupdates.sh", "message": "Removing rubbish from /ramtmp/20230107-splunk.txt"}&lt;BR /&gt;{"tstamp": "2023-01-07 16:28:43", "severity": "INFO", "process": "dailyupdates.sh", "message": "Sorting /ramtmp/20230107-splunk.txt"}&lt;BR /&gt;{"tstamp": "2023-01-07 16:57:07", "severity": "INFO", "process": "dailyupdates.sh", "message": "Converting all domains in /ramtmp/20230107-alldomains.txt to lowercase"}&lt;/P&gt;
&lt;P&gt;{"tstamp": "2023-01-07 16:57:38", "severity": "INFO", "process": "dailyupdates.sh", "message": "Sorting /ramtmp/20230107-alldomains.txt"}&lt;/P&gt;
&lt;P&gt;According jsonlint these are valid jsons. I'm using the stand _json sourcetype.&lt;/P&gt;
&lt;P&gt;Any idea what is wrong?&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Karl&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Jan 2023 16:22:40 GMT</pubDate>
    <dc:creator>Cyb0rg42</dc:creator>
    <dc:date>2023-01-09T16:22:40Z</dc:date>
    <item>
      <title>Why the error while ingesting a JSON file "Jsonlinebreaker parsing error unexpected character /"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-the-error-while-ingesting-a-JSON-file-quot-Jsonlinebreaker/m-p/626299#M107601</link>
      <description>&lt;P&gt;I'm trying to ingest a json file and got the following error:&lt;/P&gt;
&lt;P&gt;splunkd.log:01-07-2023 00:42:51.375 +0100 ERROR JsonLineBreaker [36024 parsing] - JSON StreamId:229865635822760533 had parsing error:Unexpected character: '/' - data_source="/opt/rfcanalyzer/var/log/housekeeping/dailyupdates.log", data_host="vrfcanalyzer.rfcanalyzer.net", data_sourcetype="_json"&lt;/P&gt;
&lt;P&gt;Splunk complains about the following jsons:&lt;/P&gt;
&lt;P&gt;{"tstamp": "2023-01-07 16:23:12", "severity": "INFO", "process": "dailyupdates.sh", "message": "Removing rubbish from /ramtmp/20230107-splunk.txt"}&lt;BR /&gt;{"tstamp": "2023-01-07 16:28:43", "severity": "INFO", "process": "dailyupdates.sh", "message": "Sorting /ramtmp/20230107-splunk.txt"}&lt;BR /&gt;{"tstamp": "2023-01-07 16:57:07", "severity": "INFO", "process": "dailyupdates.sh", "message": "Converting all domains in /ramtmp/20230107-alldomains.txt to lowercase"}&lt;/P&gt;
&lt;P&gt;{"tstamp": "2023-01-07 16:57:38", "severity": "INFO", "process": "dailyupdates.sh", "message": "Sorting /ramtmp/20230107-alldomains.txt"}&lt;/P&gt;
&lt;P&gt;According jsonlint these are valid jsons. I'm using the stand _json sourcetype.&lt;/P&gt;
&lt;P&gt;Any idea what is wrong?&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Karl&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 16:22:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-the-error-while-ingesting-a-JSON-file-quot-Jsonlinebreaker/m-p/626299#M107601</guid>
      <dc:creator>Cyb0rg42</dc:creator>
      <dc:date>2023-01-09T16:22:40Z</dc:date>
    </item>
  </channel>
</rss>

