<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: json messages not always indexed in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-is-causing-json-messages-to-not-always-be-indexed/m-p/646740#M109974</link>
    <description>&lt;P&gt;Hello dhuynh, there are a few possible reasons this could be happening. First, please check for payload character set issues (such as non UTF-8 characters, which can cause JSON to break. Also, check the splunk logs for errors. You can find HEC parsing errors in the _introspection index.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jun 2023 04:15:20 GMT</pubDate>
    <dc:creator>nyc_jason</dc:creator>
    <dc:date>2023-06-13T04:15:20Z</dc:date>
    <item>
      <title>What is causing json messages to not always be indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-causing-json-messages-to-not-always-be-indexed/m-p/646732#M109973</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;For one of our client we are sending in json log data via log4j2 to the splunk cloud HEC token.&lt;/P&gt;
&lt;P&gt;we are using the /event/collector/raw endpoint.&lt;/P&gt;
&lt;P&gt;What I notice is that the fields are not extracted consistently. We do not see any pattern in our process so we cannot pinpoint the exact location of the issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dhuynh_0-1686606054908.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25799i5BDF997DB6E360F1/image-size/large?v=v2&amp;amp;px=999" role="button" title="dhuynh_0-1686606054908.png" alt="dhuynh_0-1686606054908.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;dhuynh_0-1686606054908.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I am using the following source type with its configs:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dhuynh_2-1686606398965.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25801iD529805137D16882/image-size/large?v=v2&amp;amp;px=999" role="button" title="dhuynh_2-1686606398965.png" alt="dhuynh_2-1686606398965.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;dhuynh_2-1686606398965.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Hopefully can someone see what might cause this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thankyou in advanced.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Duy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 13:47:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-causing-json-messages-to-not-always-be-indexed/m-p/646732#M109973</guid>
      <dc:creator>dhuynh</dc:creator>
      <dc:date>2023-06-13T13:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: json messages not always indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-causing-json-messages-to-not-always-be-indexed/m-p/646740#M109974</link>
      <description>&lt;P&gt;Hello dhuynh, there are a few possible reasons this could be happening. First, please check for payload character set issues (such as non UTF-8 characters, which can cause JSON to break. Also, check the splunk logs for errors. You can find HEC parsing errors in the _introspection index.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 04:15:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-causing-json-messages-to-not-always-be-indexed/m-p/646740#M109974</guid>
      <dc:creator>nyc_jason</dc:creator>
      <dc:date>2023-06-13T04:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: json messages not always indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-causing-json-messages-to-not-always-be-indexed/m-p/646797#M109982</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/124800"&gt;@nyc_jason&lt;/a&gt;&amp;nbsp; thankyou for your fast reply.&lt;/P&gt;&lt;P&gt;when checking the _introspection index I dont see any parsing error. Everything gets parsed correctly. what is weird is that it happens randomly. so when I rerun the process again then the data might be parsed correctly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 11:42:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-causing-json-messages-to-not-always-be-indexed/m-p/646797#M109982</guid>
      <dc:creator>dhuynh</dc:creator>
      <dc:date>2023-06-13T11:42:02Z</dc:date>
    </item>
  </channel>
</rss>

