<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic REST input JSON event break in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/REST-input-JSON-event-break/m-p/697575#M115708</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Need an urgent help.&lt;/P&gt;&lt;P&gt;I am using REST API Modular input and the problem is i am not able to set the parameter for event breaking, below is the sample log.&lt;/P&gt;&lt;P&gt;{ "User" : [ { "record_id" : "2", "email_address" : "dsfsdf@dfdf.net", "email_address_id" : "", "email_type" : "", "email_creation_date" : "", "email_last_update_date" : "2024-08-23T05:28:43.091+00:00", "user_id" : "54216542", "username" : "Audit.Test1", "suspended" : false, "person_id" : "", "credentials_email_sent" : "", "user_guid" : "21SD6F546S2SD5F46", "user_creation_date" : "2024-08-23T05:28:42.000+00:00", "user_last_update_date" : "2024-08-23T05:28:44.000+00:00" }, { "record_id" : "3", "email_address" : "XDCFSD@dfdf.net", "email_address_id" : "", "email_type" : "", "email_creation_date" : "", "email_last_update_date" : "2024-08-28T06:42:43.736+00:00", "user_id" : "300000019394603", "username" : "Assessment.Integration", "suspended" : false, "person_id" : "", "credentials_email_sent" : "", "user_guid" : "21SD6F546S2SD5F46545SDS45S", "user_creation_date" : "2024-08-28T06:42:43.000+00:00", "user_last_update_date" : "2024-08-28T06:42:47.000+00:00" }, { "record_id" : "1", "email_address" : "dfds@dfwsfe.com", "email_address_id" : "", "email_type" : "", "email_creation_date" : "", "email_last_update_date" : "2024-08-06T13:27:34.085+00:00", "user_id" : "5612156498213", "username" : "dfsv", "suspended" : false, "person_id" : "56121564963", "credentials_email_sent" : "", "user_guid" : "D564FSD2F8WEGV216S", "user_creation_date" : "2024-08-06T13:29:00.000+00:00", "user_last_update_date" : "2024-08-06T13:29:47.224+00:00" } ]}&lt;/P&gt;</description>
    <pubDate>Wed, 28 Aug 2024 10:46:02 GMT</pubDate>
    <dc:creator>zubairsp</dc:creator>
    <dc:date>2024-08-28T10:46:02Z</dc:date>
    <item>
      <title>REST input JSON event break</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/REST-input-JSON-event-break/m-p/697575#M115708</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Need an urgent help.&lt;/P&gt;&lt;P&gt;I am using REST API Modular input and the problem is i am not able to set the parameter for event breaking, below is the sample log.&lt;/P&gt;&lt;P&gt;{ "User" : [ { "record_id" : "2", "email_address" : "dsfsdf@dfdf.net", "email_address_id" : "", "email_type" : "", "email_creation_date" : "", "email_last_update_date" : "2024-08-23T05:28:43.091+00:00", "user_id" : "54216542", "username" : "Audit.Test1", "suspended" : false, "person_id" : "", "credentials_email_sent" : "", "user_guid" : "21SD6F546S2SD5F46", "user_creation_date" : "2024-08-23T05:28:42.000+00:00", "user_last_update_date" : "2024-08-23T05:28:44.000+00:00" }, { "record_id" : "3", "email_address" : "XDCFSD@dfdf.net", "email_address_id" : "", "email_type" : "", "email_creation_date" : "", "email_last_update_date" : "2024-08-28T06:42:43.736+00:00", "user_id" : "300000019394603", "username" : "Assessment.Integration", "suspended" : false, "person_id" : "", "credentials_email_sent" : "", "user_guid" : "21SD6F546S2SD5F46545SDS45S", "user_creation_date" : "2024-08-28T06:42:43.000+00:00", "user_last_update_date" : "2024-08-28T06:42:47.000+00:00" }, { "record_id" : "1", "email_address" : "dfds@dfwsfe.com", "email_address_id" : "", "email_type" : "", "email_creation_date" : "", "email_last_update_date" : "2024-08-06T13:27:34.085+00:00", "user_id" : "5612156498213", "username" : "dfsv", "suspended" : false, "person_id" : "56121564963", "credentials_email_sent" : "", "user_guid" : "D564FSD2F8WEGV216S", "user_creation_date" : "2024-08-06T13:29:00.000+00:00", "user_last_update_date" : "2024-08-06T13:29:47.224+00:00" } ]}&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 10:46:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/REST-input-JSON-event-break/m-p/697575#M115708</guid>
      <dc:creator>zubairsp</dc:creator>
      <dc:date>2024-08-28T10:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: REST input JSON event break</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/REST-input-JSON-event-break/m-p/697581#M115711</link>
      <description>&lt;P&gt;Do you need help how to configure the props.conf or where to configure it?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 11:35:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/REST-input-JSON-event-break/m-p/697581#M115711</guid>
      <dc:creator>PaulPanther</dc:creator>
      <dc:date>2024-08-28T11:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: REST input JSON event break</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/REST-input-JSON-event-break/m-p/697583#M115712</link>
      <description>&lt;P&gt;Sorry for not being clearer, however i need help with props attributes and regex to match event break&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 11:46:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/REST-input-JSON-event-break/m-p/697583#M115712</guid>
      <dc:creator>zubairsp</dc:creator>
      <dc:date>2024-08-28T11:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: REST input JSON event break</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/REST-input-JSON-event-break/m-p/697584#M115713</link>
      <description>&lt;P&gt;Hi Zubair,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[YOUR_SOURCETYPE]
SHOULD_LINEMERGE=true
LINE_BREAKER=(, )
TRUNCATE=9999999
BREAK_ONLY_BEFORE={
MUST_BREAK_AFTER=}
SEDCMD-cleanup-before=s/^\{ "User" : \[\s\{/{/g
SEDCMD-cleanup-after-2=s/\s\[\}/}/g&lt;/LI-CODE&gt;&lt;P&gt;It's best if you can run that on a test instance first with some sample data to see how it works for you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 11:58:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/REST-input-JSON-event-break/m-p/697584#M115713</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2024-08-28T11:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: REST input JSON event break</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/REST-input-JSON-event-break/m-p/697717#M115727</link>
      <description>&lt;P&gt;Anyone interested,&lt;/P&gt;&lt;P&gt;This solution worked just fine, however i ended up using the Addon builder instead since it was clean with less efforts.&lt;/P&gt;&lt;P&gt;There is an option in Addon builder called "event extraction settings" here i simply used the following settings $.User&lt;/P&gt;&lt;P&gt;This setting will break the events and also field/value pairs.&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 13:59:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/REST-input-JSON-event-break/m-p/697717#M115727</guid>
      <dc:creator>zubairsp</dc:creator>
      <dc:date>2024-08-29T13:59:52Z</dc:date>
    </item>
  </channel>
</rss>

