<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do we assign each JSON document to a distinct event? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364358#M66339</link>
    <description>&lt;P&gt;Hi @ddrillic,&lt;/P&gt;

&lt;P&gt;Can you please provide some sample data?&lt;/P&gt;</description>
    <pubDate>Fri, 22 Dec 2017 02:43:26 GMT</pubDate>
    <dc:creator>harsmarvania57</dc:creator>
    <dc:date>2017-12-22T02:43:26Z</dc:date>
    <item>
      <title>How do we assign each JSON document to a distinct event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364357#M66338</link>
      <description>&lt;P&gt;We have a case in which multiple json documents are being clamped together into one Splunk event. How do we untangle it?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2017 22:48:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364357#M66338</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-12-21T22:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: How do we assign each JSON document to a distinct event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364358#M66339</link>
      <description>&lt;P&gt;Hi @ddrillic,&lt;/P&gt;

&lt;P&gt;Can you please provide some sample data?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 02:43:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364358#M66339</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-12-22T02:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: How do we assign each JSON document to a distinct event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364359#M66340</link>
      <description>&lt;P&gt;@ddrillic also add what is your current sourcetype stanza for JSON data?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 03:17:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364359#M66340</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-12-22T03:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: How do we assign each JSON document to a distinct event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364360#M66341</link>
      <description>&lt;P&gt;Hi ddrillic,&lt;/P&gt;

&lt;P&gt;This usually happens when you have brackets at the beginning of your JSON containing the entire document. It makes it as if the entire document is a value for one of the elements. You should set up a sedcmd in your props to clear this up, or clear it via script before the data gets into Splunk.&lt;/P&gt;

&lt;P&gt;If you post a copy of the header/end of your JSON file I can help you set up the sedcmd.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
David&lt;/P&gt;</description>
      <pubDate>Sat, 23 Dec 2017 11:48:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364360#M66341</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2017-12-23T11:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: How do we assign each JSON document to a distinct event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364361#M66342</link>
      <description>&lt;P&gt;@niketnilay, sorry for the delay. We didn't set anything in the configuration files.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 22:06:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364361#M66342</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-01-03T22:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: How do we assign each JSON document to a distinct event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364362#M66343</link>
      <description>&lt;P&gt;Interesting - it looks like &lt;CODE&gt;{"userDetails":{...."message":null}&lt;/CODE&gt; followed by another one like this one - &lt;CODE&gt;{"userDetails":{...."message":null}&lt;/CODE&gt;...&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 22:12:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364362#M66343</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-01-03T22:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: How do we assign each JSON document to a distinct event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364363#M66344</link>
      <description>&lt;P&gt;You would need to set appropriate Line breaking configuration for your sourcetype, and for which we'd need some sample data (mask anything that's sensitive), and some details on how you'd want to break that sample event.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 22:14:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364363#M66344</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-01-03T22:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: How do we assign each JSON document to a distinct event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364364#M66345</link>
      <description>&lt;P&gt;It looks like - &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;{"userDetails":{sensitive data},"message":null}
{"userDetails":{sensitive data},"message":null}
{"userDetails":{sensitive data},"message":null}
{"userDetails":{sensitive data},"message":null}
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 03 Jan 2018 22:29:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364364#M66345</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-01-03T22:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: How do we assign each JSON document to a distinct event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364365#M66346</link>
      <description>&lt;P&gt;Try to use following in props.conf on Indexer(s)/Heavy Forwarder(s) whichever comes first.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[YourSourceTypeHere]
SHOULD_LINEMERGE = false
LINE_BREAKER = ([\r\n]+)(?=\{\"userDetails\"\:)
..other timestamp extraction attributes...
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 03 Jan 2018 22:40:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364365#M66346</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-01-03T22:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: How do we assign each JSON document to a distinct event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364366#M66347</link>
      <description>&lt;P&gt;Gorgeous as usual ; -) &lt;BR /&gt;
But, any way to avoid the hard-coding of &lt;CODE&gt;userDetails&lt;/CODE&gt;?&lt;/P&gt;

&lt;P&gt;Needless to say - working as expected !!!!!!!!!!&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 22:51:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364366#M66347</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-01-03T22:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: How do we assign each JSON document to a distinct event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364367#M66348</link>
      <description>&lt;P&gt;Well, you generally need to put an anchor for identifying line start. You can try with &lt;CODE&gt;([\r\n]+)(?=\{\"\w+\"\:)&lt;/CODE&gt; to see if that works for. Since we don't have full events, we can't say for sure that it'll work (there may be other entries matching that pattern).&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 22:53:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364367#M66348</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-01-03T22:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: How do we assign each JSON document to a distinct event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364368#M66349</link>
      <description>&lt;P&gt;if your lines are always starting with a new element you can go for this config :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[yourSourcetype]
BREAK_ONLY_BEFORE = ^\{
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 04 Jan 2018 09:32:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364368#M66349</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2018-01-04T09:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: How do we assign each JSON document to a distinct event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364369#M66350</link>
      <description>&lt;P&gt;&lt;CODE&gt;LINE_BREAKER&lt;/CODE&gt; would be a much better approach than &lt;CODE&gt;BREAK_ONLY_BEFORE&lt;/CODE&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 15:24:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364369#M66350</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-01-30T15:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: How do we assign each JSON document to a distinct event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364370#M66351</link>
      <description>&lt;P&gt;why do you say that ? &lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 17:36:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364370#M66351</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2018-01-30T17:36:36Z</dc:date>
    </item>
    <item>
      <title>Re: How do we assign each JSON document to a distinct event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364371#M66352</link>
      <description>&lt;P&gt;If you set &lt;CODE&gt;SHOULD_LINEMERGE = false&lt;/CODE&gt; and use &lt;CODE&gt;LINE_BREAKER&lt;/CODE&gt;, this will skip the merging pipeline and give a performance boost &lt;/P&gt;

&lt;P&gt;&lt;A href="http://wiki.splunk.com/Community:HowIndexingWorks"&gt;http://wiki.splunk.com/Community:HowIndexingWorks&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 18:03:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-we-assign-each-JSON-document-to-a-distinct-event/m-p/364371#M66352</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-01-30T18:03:14Z</dc:date>
    </item>
  </channel>
</rss>

