<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is Hunk outputting space separated values from HDFS/Hive as JSON in search results? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225832#M44135</link>
    <description>&lt;P&gt;Fair enough, but why do we see one level of nesting for some tables and two levels of nesting for other tables, while the hive and the hdfs data look identical?&lt;/P&gt;</description>
    <pubDate>Thu, 03 Mar 2016 15:07:17 GMT</pubDate>
    <dc:creator>ddrillic</dc:creator>
    <dc:date>2016-03-03T15:07:17Z</dc:date>
    <item>
      <title>Why is Hunk outputting space separated values from HDFS/Hive as JSON in search results?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225824#M44127</link>
      <description>&lt;P&gt;We see the following:&lt;BR /&gt;
 &lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/1092iE7D58F7987C810C4/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;On the HDFS file system, the values are space separated. How can we "fix" the loading process so it won't show as json?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2016 17:12:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225824#M44127</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-03-01T17:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Hunk outputting space separated values from HDFS/Hive as JSON in search results?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225825#M44128</link>
      <description>&lt;P&gt;Hi Dan&lt;/P&gt;

&lt;P&gt;Are you saying that the records are not actually JSON or that we have extra spaces to deal with or that you don't want to view the records as JSON?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2016 17:33:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225825#M44128</guid>
      <dc:creator>Claw</dc:creator>
      <dc:date>2016-03-01T17:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Hunk outputting space separated values from HDFS/Hive as JSON in search results?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225826#M44129</link>
      <description>&lt;P&gt;Hi David,&lt;/P&gt;

&lt;P&gt;The records are in text, space separated. The preferred way to view the data is in a non-json way. What do you think?&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Dan &lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2016 18:18:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225826#M44129</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-03-01T18:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Hunk outputting space separated values from HDFS/Hive as JSON in search results?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225827#M44130</link>
      <description>&lt;P&gt;Dan: maybe a sample of the input would help us understand?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2016 18:41:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225827#M44130</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2016-03-01T18:41:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Hunk outputting space separated values from HDFS/Hive as JSON in search results?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225828#M44131</link>
      <description>&lt;P&gt;The input looks like - &lt;BR /&gt;
01Arabian                                                                                             U2007-05-08TSUAS63 2016-01-06201&lt;BR /&gt;
6-01-06&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2016 19:35:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225828#M44131</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-03-01T19:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Hunk outputting space separated values from HDFS/Hive as JSON in search results?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225829#M44132</link>
      <description>&lt;P&gt;If you are using Hunk with Hive, what you see is the expected behavior.&lt;/P&gt;

&lt;P&gt;Hunk will display the data in a JSON format if you are using Hive metadata, Parquet, Avro, SEQ, and CSV.&lt;BR /&gt;
If you are using Hunk without Hive (or without any of the above file formats), you will see the data as the normal Splunk log format&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2016 01:37:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225829#M44132</guid>
      <dc:creator>rdagan_splunk</dc:creator>
      <dc:date>2016-03-02T01:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Hunk outputting space separated values from HDFS/Hive as JSON in search results?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225830#M44133</link>
      <description>&lt;P&gt;Hi Raanan, David,&lt;/P&gt;

&lt;P&gt;The thing is that for some tables we see one level of json nesting and for others we see a nesting for each field with the creation of new fields on the left pane.&lt;/P&gt;

&lt;P&gt;So, that's the issue.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Dan&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2016 14:08:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225830#M44133</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-03-02T14:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Hunk outputting space separated values from HDFS/Hive as JSON in search results?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225831#M44134</link>
      <description>&lt;P&gt;Hi Dan,&lt;BR /&gt;
Yes JSON nesting is also the expected behavior.  So when you see nesting in the Json file, we visualize it using the A.B notation and we use the plus sign to enable users to expend the nesting. &lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2016 21:47:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225831#M44134</guid>
      <dc:creator>rdagan_splunk</dc:creator>
      <dc:date>2016-03-02T21:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Hunk outputting space separated values from HDFS/Hive as JSON in search results?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225832#M44135</link>
      <description>&lt;P&gt;Fair enough, but why do we see one level of nesting for some tables and two levels of nesting for other tables, while the hive and the hdfs data look identical?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2016 15:07:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225832#M44135</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-03-03T15:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Hunk outputting space separated values from HDFS/Hive as JSON in search results?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225833#M44136</link>
      <description>&lt;P&gt;Raanan, working with Jeff and we realized that the extra json level happens when the hive data definition holds Char(N). When the hive data definition is String, we see the expected presentation.&lt;/P&gt;

&lt;P&gt;Just to keep in mind, the upgrade of the hive libraries last week solved the immediate fatal error when issuing a query. Now we have a different related issue.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2016 22:46:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225833#M44136</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-03-03T22:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Hunk outputting space separated values from HDFS/Hive as JSON in search results?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225834#M44137</link>
      <description>&lt;P&gt;As Dan commented above... we got to the bottom of the issue and it appears that it's occurring because the Hive table serving the above data has been defined with a char(n) datatype for text as opposed to string. While the workaround posted here: &lt;A href="https://answers.splunk.com/answers/372130/hunk-630-doesnt-seem-to-work-with-hive-version-013.html"&gt;https://answers.splunk.com/answers/372130/hunk-630-doesnt-seem-to-work-with-hive-version-013.html&lt;/A&gt; will allow char(n) tables to be input without error, they still do display the data a little funky. At this time, it appears a Hunk update (current version is 6.3.x) to better support char(n) will be required for it to operate the same as string.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2016 14:05:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225834#M44137</guid>
      <dc:creator>JeffWiedemann</dc:creator>
      <dc:date>2016-03-07T14:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Hunk outputting space separated values from HDFS/Hive as JSON in search results?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225835#M44138</link>
      <description>&lt;P&gt;char(n) should now be supported in splunk / hunk 6.4.1 maintenance release:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/379387/hunk-hive-and-decimalnn.html#answer-405335"&gt;https://answers.splunk.com/answers/379387/hunk-hive-and-decimalnn.html#answer-405335&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2016 16:12:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225835#M44138</guid>
      <dc:creator>splunkIT</dc:creator>
      <dc:date>2016-05-25T16:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Hunk outputting space separated values from HDFS/Hive as JSON in search results?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225836#M44139</link>
      <description>&lt;P&gt;That's interesting as we just upgraded to 6.4.1&lt;/P&gt;</description>
      <pubDate>Sun, 29 May 2016 00:45:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Hunk-outputting-space-separated-values-from-HDFS-Hive-as/m-p/225836#M44139</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-05-29T00:45:50Z</dc:date>
    </item>
  </channel>
</rss>

