<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ERROR JsonLineBreaker in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-JsonLineBreaker/m-p/422623#M74239</link>
    <description>&lt;P&gt;Yup, I removed splunkd.log from smn-sn-util01 and the issue persisted. Here's the output of the command:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/opt/splunkforwarder/etc/apps/search/default/props.conf [splunkd]
/opt/splunkforwarder/etc/system/local/props.conf        AUTO_KV_JSON = false
/opt/splunkforwarder/etc/apps/search/default/props.conf EXTRACT-fields = (?i)^(?:[^ ]* ){2}(?:[+\-]\d+ )?(?P&amp;lt;log_level&amp;gt;[^ ]*)\s+(?P&amp;lt;component&amp;gt;[^ ]+) - (?P&amp;lt;message&amp;gt;.+)
/opt/splunkforwarder/etc/system/local/props.conf        INDEXED_EXTRACTIONS = JSON
/opt/splunkforwarder/etc/system/local/props.conf        KV_MODE = none
/opt/splunkforwarder/etc/system/local/props.conf        TIMESTAMP_FIELDS = _time
/opt/splunkforwarder/etc/system/local/props.conf        TZ = UTC
/opt/splunkforwarder/etc/system/local/props.conf        AUTO_KV_JSON = false
/opt/splunkforwarder/etc/system/local/props.conf        INDEXED_EXTRACTIONS = JSON
/opt/splunkforwarder/etc/system/local/props.conf        KV_MODE = none
/opt/splunkforwarder/etc/system/local/props.conf        TIMESTAMP_FIELDS = _time
/opt/splunkforwarder/etc/system/local/props.conf        TIME_FORMAT = %s
/opt/splunkforwarder/etc/system/local/props.conf        TZ = UTC
/opt/splunkforwarder/etc/system/local/props.conf        AUTO_KV_JSON = false
/opt/splunkforwarder/etc/system/local/props.conf        TZ = UTC
/opt/splunkforwarder/etc/system/local/props.conf        AUTO_KV_JSON = false
/opt/splunkforwarder/etc/system/local/props.conf        INDEXED_EXTRACTIONS = JSON
/opt/splunkforwarder/etc/system/local/props.conf        KV_MODE = none
/opt/splunkforwarder/etc/system/local/props.conf        TIMESTAMP_FIELDS = _time
/opt/splunkforwarder/etc/system/local/props.conf        TIME_FORMAT = %s
/opt/splunkforwarder/etc/system/local/props.conf        TZ = UTC
/opt/splunkforwarder/etc/system/local/props.conf        AUTO_KV_JSON = false
/opt/splunkforwarder/etc/system/local/props.conf        INDEXED_EXTRACTIONS = JSON
/opt/splunkforwarder/etc/system/local/props.conf        KV_MODE = none
/opt/splunkforwarder/etc/system/local/props.conf        TIMESTAMP_FIELDS = _time
/opt/splunkforwarder/etc/system/local/props.conf        TIME_FORMAT = %s
/opt/splunkforwarder/etc/system/local/props.conf        TZ = UTC
/opt/splunkforwarder/etc/system/local/props.conf        AUTO_KV_JSON = false
/opt/splunkforwarder/etc/system/local/props.conf        INDEXED_EXTRACTIONS = JSON
/opt/splunkforwarder/etc/system/local/props.conf        TIMESTAMP_FIELDS = _time
/opt/splunkforwarder/etc/system/local/props.conf        TZ = UTC
/opt/splunkforwarder/etc/system/local/props.conf        AUTO_KV_JSON = false
/opt/splunkforwarder/etc/system/local/props.conf        INDEXED_EXTRACTIONS = JSON
/opt/splunkforwarder/etc/system/local/props.conf        KV_MODE = none
/opt/splunkforwarder/etc/system/local/props.conf        TIMESTAMP_FIELDS = _time
/opt/splunkforwarder/etc/system/local/props.conf        TZ = UTC
/opt/splunkforwarder/etc/system/local/props.conf        AUTO_KV_JSON = false
/opt/splunkforwarder/etc/system/local/props.conf        INDEXED_EXTRACTIONS = JSON
/opt/splunkforwarder/etc/system/local/props.conf        KV_MODE = none
/opt/splunkforwarder/etc/system/local/props.conf        TIMESTAMP_FIELDS = _time
/opt/splunkforwarder/etc/system/local/props.conf        TIME_FORMAT = %s
/opt/splunkforwarder/etc/system/local/props.conf        TZ = UTC
/opt/splunkforwarder/etc/system/local/props.conf        AUTO_KV_JSON = false
/opt/splunkforwarder/etc/system/local/props.conf        INDEXED_EXTRACTIONS = JSON
/opt/splunkforwarder/etc/system/local/props.conf        KV_MODE = none
/opt/splunkforwarder/etc/system/local/props.conf        TIMESTAMP_FIELDS = _time
/opt/splunkforwarder/etc/system/local/props.conf        TIME_FORMAT = %s
/opt/splunkforwarder/etc/system/local/props.conf        TZ = UTC
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 23 Apr 2019 21:08:07 GMT</pubDate>
    <dc:creator>anayar</dc:creator>
    <dc:date>2019-04-23T21:08:07Z</dc:date>
    <item>
      <title>ERROR JsonLineBreaker</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-JsonLineBreaker/m-p/422621#M74237</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;I don’t know exactly how long this has been going on but I noticed today that the following error is being spammed into the /opt/splunkforwarder/var/log/splunk/splunkd.log file on our system.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;04-22-2019 17:36:10.474 -0700 ERROR JsonLineBreaker - JSON StreamId:14919777892573414995 had parsing error:Unexpected character: '4' - data_source="/opt/splunkforwarder/var/log/splunk/splunkd.log", data_host="smn-sn-util01", data_sourcetype="splunkd"
04-22-2019 17:36:10.474 -0700 ERROR JsonLineBreaker - JSON StreamId:14919777892573414995 had parsing error:Unexpected character: '4' - data_source="/opt/splunkforwarder/var/log/splunk/splunkd.log", data_host="smn-sn-util01", data_sourcetype="splunkd"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;There's also this error which occasionally pops up in the log but not nearly as frequently as the one above:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;04-22-2019 17:47:05.009 -0700 ERROR JsonLineBreaker - JSON StreamId:8970828008188520838 had parsing error:Unexpected character while looking for value: 'A' - data_source="/var/log/messages", data_host="smn-sn-util01", data_sourcetype="syslog"
04-22-2019 17:47:05.009 -0700 ERROR JsonLineBreaker - JSON StreamId:8970828008188520838 had parsing error:Unexpected character while looking for value: 'A' - data_source="/var/log/messages", data_host="smn-sn-util01", data_sourcetype="syslog"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I tried stopping splunk, removing all the splunkd.log* files, and then restarting splunk but the error continues to show up in the logs. Any ideas as to what may be causing this?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2019 18:02:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-JsonLineBreaker/m-p/422621#M74237</guid>
      <dc:creator>anayar</dc:creator>
      <dc:date>2019-04-23T18:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR JsonLineBreaker</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-JsonLineBreaker/m-p/422622#M74238</link>
      <description>&lt;P&gt;You removed splunkd.log file from host &lt;CODE&gt;smn-sn-util01&lt;/CODE&gt;? Also, you can run btool command on that host for splunkd sourcetype and provide output here?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/opt/splunkforwarder/bin/splunk btool props list splunkd --debug | grep -v system/default
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 23 Apr 2019 19:33:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-JsonLineBreaker/m-p/422622#M74238</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-04-23T19:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR JsonLineBreaker</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-JsonLineBreaker/m-p/422623#M74239</link>
      <description>&lt;P&gt;Yup, I removed splunkd.log from smn-sn-util01 and the issue persisted. Here's the output of the command:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/opt/splunkforwarder/etc/apps/search/default/props.conf [splunkd]
/opt/splunkforwarder/etc/system/local/props.conf        AUTO_KV_JSON = false
/opt/splunkforwarder/etc/apps/search/default/props.conf EXTRACT-fields = (?i)^(?:[^ ]* ){2}(?:[+\-]\d+ )?(?P&amp;lt;log_level&amp;gt;[^ ]*)\s+(?P&amp;lt;component&amp;gt;[^ ]+) - (?P&amp;lt;message&amp;gt;.+)
/opt/splunkforwarder/etc/system/local/props.conf        INDEXED_EXTRACTIONS = JSON
/opt/splunkforwarder/etc/system/local/props.conf        KV_MODE = none
/opt/splunkforwarder/etc/system/local/props.conf        TIMESTAMP_FIELDS = _time
/opt/splunkforwarder/etc/system/local/props.conf        TZ = UTC
/opt/splunkforwarder/etc/system/local/props.conf        AUTO_KV_JSON = false
/opt/splunkforwarder/etc/system/local/props.conf        INDEXED_EXTRACTIONS = JSON
/opt/splunkforwarder/etc/system/local/props.conf        KV_MODE = none
/opt/splunkforwarder/etc/system/local/props.conf        TIMESTAMP_FIELDS = _time
/opt/splunkforwarder/etc/system/local/props.conf        TIME_FORMAT = %s
/opt/splunkforwarder/etc/system/local/props.conf        TZ = UTC
/opt/splunkforwarder/etc/system/local/props.conf        AUTO_KV_JSON = false
/opt/splunkforwarder/etc/system/local/props.conf        TZ = UTC
/opt/splunkforwarder/etc/system/local/props.conf        AUTO_KV_JSON = false
/opt/splunkforwarder/etc/system/local/props.conf        INDEXED_EXTRACTIONS = JSON
/opt/splunkforwarder/etc/system/local/props.conf        KV_MODE = none
/opt/splunkforwarder/etc/system/local/props.conf        TIMESTAMP_FIELDS = _time
/opt/splunkforwarder/etc/system/local/props.conf        TIME_FORMAT = %s
/opt/splunkforwarder/etc/system/local/props.conf        TZ = UTC
/opt/splunkforwarder/etc/system/local/props.conf        AUTO_KV_JSON = false
/opt/splunkforwarder/etc/system/local/props.conf        INDEXED_EXTRACTIONS = JSON
/opt/splunkforwarder/etc/system/local/props.conf        KV_MODE = none
/opt/splunkforwarder/etc/system/local/props.conf        TIMESTAMP_FIELDS = _time
/opt/splunkforwarder/etc/system/local/props.conf        TIME_FORMAT = %s
/opt/splunkforwarder/etc/system/local/props.conf        TZ = UTC
/opt/splunkforwarder/etc/system/local/props.conf        AUTO_KV_JSON = false
/opt/splunkforwarder/etc/system/local/props.conf        INDEXED_EXTRACTIONS = JSON
/opt/splunkforwarder/etc/system/local/props.conf        TIMESTAMP_FIELDS = _time
/opt/splunkforwarder/etc/system/local/props.conf        TZ = UTC
/opt/splunkforwarder/etc/system/local/props.conf        AUTO_KV_JSON = false
/opt/splunkforwarder/etc/system/local/props.conf        INDEXED_EXTRACTIONS = JSON
/opt/splunkforwarder/etc/system/local/props.conf        KV_MODE = none
/opt/splunkforwarder/etc/system/local/props.conf        TIMESTAMP_FIELDS = _time
/opt/splunkforwarder/etc/system/local/props.conf        TZ = UTC
/opt/splunkforwarder/etc/system/local/props.conf        AUTO_KV_JSON = false
/opt/splunkforwarder/etc/system/local/props.conf        INDEXED_EXTRACTIONS = JSON
/opt/splunkforwarder/etc/system/local/props.conf        KV_MODE = none
/opt/splunkforwarder/etc/system/local/props.conf        TIMESTAMP_FIELDS = _time
/opt/splunkforwarder/etc/system/local/props.conf        TIME_FORMAT = %s
/opt/splunkforwarder/etc/system/local/props.conf        TZ = UTC
/opt/splunkforwarder/etc/system/local/props.conf        AUTO_KV_JSON = false
/opt/splunkforwarder/etc/system/local/props.conf        INDEXED_EXTRACTIONS = JSON
/opt/splunkforwarder/etc/system/local/props.conf        KV_MODE = none
/opt/splunkforwarder/etc/system/local/props.conf        TIMESTAMP_FIELDS = _time
/opt/splunkforwarder/etc/system/local/props.conf        TIME_FORMAT = %s
/opt/splunkforwarder/etc/system/local/props.conf        TZ = UTC
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 23 Apr 2019 21:08:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-JsonLineBreaker/m-p/422623#M74239</guid>
      <dc:creator>anayar</dc:creator>
      <dc:date>2019-04-23T21:08:07Z</dc:date>
    </item>
  </channel>
</rss>

