<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: import json file in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631187#M108182</link>
    <description>&lt;P&gt;I have added&amp;nbsp;TRUNCATE = 0 at&amp;nbsp;/opt/splunk/etc/system/props.conf and the file didn't upload it at all (&lt;/P&gt;&lt;P&gt;I cannot see anywhere else to have it&lt;/P&gt;&lt;P&gt;&amp;nbsp;/opt/splunk/etc/system/local# grep -i -r "TRUNCATE" .&lt;BR /&gt;./props.conf:TRUNCATE = 0&lt;BR /&gt;./limits.conf:truncate_report = 0&lt;/P&gt;</description>
    <pubDate>Thu, 16 Feb 2023 12:52:43 GMT</pubDate>
    <dc:creator>vernikose</dc:creator>
    <dc:date>2023-02-16T12:52:43Z</dc:date>
    <item>
      <title>How to import json file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631173#M108179</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I am trying to import a json file to SPLUNK. It seems that the file is imported into one event but not all of it, it looks like that the file is imported by 10% (or less).&lt;/P&gt;
&lt;P&gt;Could it be because of a configuration that I have to change?&lt;/P&gt;
&lt;P&gt;the file is of this format&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{"resultsPerPage":344,"startIndex":0,"totalResults":344,"format":"NVD_CVE","version":"2.0","timestamp":"2023-02-15T09:42:40.560","vulnerabilities":[{"cve":{"id":"CVE-2013-10012","sourceIdentifier":"cna@vuldb.com","published":"2023-01-16T11:15:10.037","lastModified":"2023-01-24T15:14:10.117","vulnStatus":"Analyzed","descriptions":[{"lang":"en","value":"A vulnerability, which was classified as critical, was found in antonbolling clan7ups. Affected is an unknown function of the component Login\/Session. The manipulation leads to sql injection. The name of the patch is 25afad571c488291033958d845830ba0a1710764. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218388."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV30":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0\/AV:A\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:L","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.1,"impactScore":3.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:A\/AC:L\/Au:S\/C:P\/I:P\/A:P","accessVector":"ADJACENT_NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":5.2},"baseSeverity":"MEDIUM","exploitabilityScore":5.1,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:clan7ups_project:clan7ups:*:*:*:*:*:*:*:*","versionEndExcluding":"2013-02-12","matchCriteriaId":"12D82AEE-3A68-4121-811C-C3462BCEAF25"}]}]}],"references":[{"url":"https:\/\/github.com\/antonbolling\/clan7ups\/commit\/25afad571c488291033958d845830ba0a1710764","source":"cna@vuldb.com","tags":["Patch","Third Party Advisory"]}&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would appreciate any help&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 15:55:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631173#M108179</guid>
      <dc:creator>vernikose</dc:creator>
      <dc:date>2023-02-16T15:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: import json file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631174#M108180</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242384"&gt;@vernikose&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If the file is bigger than 10000 characters and Splunk tires to import as one event your should be hitting TRUNCATE=10000 default limit. You can change this parameter on your sourcetype and try again.&lt;/P&gt;&lt;P&gt;In order to split the file into 344 events you should set LINE_BREAKER settings accordingly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 12:03:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631174#M108180</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2023-02-16T12:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: import json file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631184#M108181</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;thanks for your feedback. I don't mind to have it in one event.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;where about do I change the&amp;nbsp;&lt;SPAN&gt;TRUNCATE=10000?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 12:41:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631184#M108181</guid>
      <dc:creator>vernikose</dc:creator>
      <dc:date>2023-02-16T12:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: import json file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631187#M108182</link>
      <description>&lt;P&gt;I have added&amp;nbsp;TRUNCATE = 0 at&amp;nbsp;/opt/splunk/etc/system/props.conf and the file didn't upload it at all (&lt;/P&gt;&lt;P&gt;I cannot see anywhere else to have it&lt;/P&gt;&lt;P&gt;&amp;nbsp;/opt/splunk/etc/system/local# grep -i -r "TRUNCATE" .&lt;BR /&gt;./props.conf:TRUNCATE = 0&lt;BR /&gt;./limits.conf:truncate_report = 0&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 12:52:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631187#M108182</guid>
      <dc:creator>vernikose</dc:creator>
      <dc:date>2023-02-16T12:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: import json file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631188#M108183</link>
      <description>&lt;P&gt;If you are using Add Data GUI method, you can add new parameter as like TRUNCATE=100000.&lt;/P&gt;&lt;P&gt;Or you should add your props.conf like below and restart Splunk.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;props.conf

[your_sourcetype]
TRUNCATE = 100000&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 12:55:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631188#M108183</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2023-02-16T12:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: import json file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631190#M108184</link>
      <description>&lt;P&gt;When I add the&amp;nbsp;TRUNCATE = 100000 the file is not uploaded. I have no results. even with&amp;nbsp;TRUNCATE = 0&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 13:11:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631190#M108184</guid>
      <dc:creator>vernikose</dc:creator>
      <dc:date>2023-02-16T13:11:28Z</dc:date>
    </item>
    <item>
      <title>Re: import json file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631193#M108185</link>
      <description>&lt;P&gt;Can you please share your full config about TRUNCATE setting? Did you enter it into the right stanza?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 13:39:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631193#M108185</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2023-02-16T13:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: import json file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631194#M108186</link>
      <description>&lt;P&gt;/opt/splunk/etc/system/local# cat props.conf&lt;BR /&gt;[test]&lt;BR /&gt;SHOULD_LINEMERGE = true&lt;BR /&gt;TRUNCATE = 100000&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 13:42:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631194#M108186</guid>
      <dc:creator>vernikose</dc:creator>
      <dc:date>2023-02-16T13:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to import json file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631274#M108194</link>
      <description>&lt;P&gt;This seems fine and should not cause problem with uploading.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can not think any reason for the problem.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 05:47:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-import-json-file/m-p/631274#M108194</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2023-02-17T05:47:38Z</dc:date>
    </item>
  </channel>
</rss>

