<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTP Event Collector: Why are double quotes not escaped for a properly formatted JSON string? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Why-are-double-quotes-not-escaped-for-a/m-p/283062#M54112</link>
    <description>&lt;P&gt;This is fixed in the next version of Splunk, 6.4 which will be shipping very soon. &lt;/P&gt;</description>
    <pubDate>Tue, 05 Apr 2016 04:30:09 GMT</pubDate>
    <dc:creator>gblock_splunk</dc:creator>
    <dc:date>2016-04-05T04:30:09Z</dc:date>
    <item>
      <title>HTTP Event Collector: Why are double quotes not escaped for a properly formatted JSON string?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Why-are-double-quotes-not-escaped-for-a/m-p/283061#M54111</link>
      <description>&lt;P&gt;A properly formatted JSON string will escape the double quotes. However the HEC does not translate that  accordingly.&lt;/P&gt;

&lt;P&gt;e.g &lt;CODE&gt;JSON message to HEC: {"event":"somefield=\"a value with spaces\""}&lt;/CODE&gt;&lt;BR /&gt;
the value for &lt;CODE&gt;somefield&lt;/CODE&gt; is &lt;CODE&gt;\"a value with spaces\"&lt;/CODE&gt;&lt;BR /&gt;
when it should have the value &lt;CODE&gt;a value with spaces&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Any information on how to rectify this would be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 23:33:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Why-are-double-quotes-not-escaped-for-a/m-p/283061#M54111</guid>
      <dc:creator>unclethan</dc:creator>
      <dc:date>2016-04-04T23:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector: Why are double quotes not escaped for a properly formatted JSON string?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Why-are-double-quotes-not-escaped-for-a/m-p/283062#M54112</link>
      <description>&lt;P&gt;This is fixed in the next version of Splunk, 6.4 which will be shipping very soon. &lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2016 04:30:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Why-are-double-quotes-not-escaped-for-a/m-p/283062#M54112</guid>
      <dc:creator>gblock_splunk</dc:creator>
      <dc:date>2016-04-05T04:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector: Why are double quotes not escaped for a properly formatted JSON string?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Why-are-double-quotes-not-escaped-for-a/m-p/283063#M54113</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We're currently using Splunk version 6.4.1 and still experiencing this bug.&lt;BR /&gt;
Can you verify if / on what version was it fixed to let us know what version should we upgrade to?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Ido&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 11:41:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Why-are-double-quotes-not-escaped-for-a/m-p/283063#M54113</guid>
      <dc:creator>IdoTwiggle</dc:creator>
      <dc:date>2016-10-18T11:41:50Z</dc:date>
    </item>
  </channel>
</rss>

