<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to write parsing configuration for json file? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-write-parsing-configuration-for-json-file/m-p/478001#M82037</link>
    <description>&lt;P&gt;Filename: xxx&lt;BR /&gt;
dest: xxx&lt;BR /&gt;
created_at: xxxx&lt;BR /&gt;
destination_port: null&lt;BR /&gt;
source: xxx&lt;BR /&gt;
username: zxx&lt;/P&gt;

&lt;P&gt;above fields are not populating and time and date field which i have added those only populating&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 02:52:03 GMT</pubDate>
    <dc:creator>vin02ptl</dc:creator>
    <dc:date>2020-09-30T02:52:03Z</dc:date>
    <item>
      <title>How to write parsing configuration for json file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-write-parsing-configuration-for-json-file/m-p/477997#M82033</link>
      <description>&lt;P&gt;My log contains multiple {} data structure and  i want to get all json field inside extracted field in splunk . How to parse?&lt;/P&gt;

&lt;P&gt;{   [-] &lt;BR /&gt;
     service:   [   [-] &lt;BR /&gt;
        {   [-] &lt;BR /&gt;
         name:  xxxxx&lt;BR /&gt;&lt;BR /&gt;
         id:    xxx &lt;BR /&gt;
        }&lt;BR /&gt;&lt;BR /&gt;
    ]&lt;BR /&gt;&lt;BR /&gt;
     Filename:   xxx&lt;BR /&gt;&lt;BR /&gt;
     dest:   xxx&lt;BR /&gt;&lt;BR /&gt;
     created_at:     xxxx&lt;BR /&gt;
     destination_port:   null&lt;BR /&gt;&lt;BR /&gt;
     source:    xxx&lt;BR /&gt;&lt;BR /&gt;
     username:   zxx&lt;BR /&gt;
}&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:52:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-write-parsing-configuration-for-json-file/m-p/477997#M82033</guid>
      <dc:creator>vin02ptl</dc:creator>
      <dc:date>2020-09-30T02:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to write parsing configuration for json file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-write-parsing-configuration-for-json-file/m-p/477998#M82034</link>
      <description>&lt;P&gt;props.conf with KV_MODE set to JSON should do the trick for you&lt;/P&gt;

&lt;P&gt;Documentation on props.conf here - &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Nov 2019 17:47:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-write-parsing-configuration-for-json-file/m-p/477998#M82034</guid>
      <dc:creator>arjunpkishore5</dc:creator>
      <dc:date>2019-11-03T17:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to write parsing configuration for json file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-write-parsing-configuration-for-json-file/m-p/477999#M82035</link>
      <description>&lt;P&gt;i have tried, but fields are not reflecting under interesting field&lt;/P&gt;</description>
      <pubDate>Sun, 03 Nov 2019 17:54:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-write-parsing-configuration-for-json-file/m-p/477999#M82035</guid>
      <dc:creator>vin02ptl</dc:creator>
      <dc:date>2019-11-03T17:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to write parsing configuration for json file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-write-parsing-configuration-for-json-file/m-p/478000#M82036</link>
      <description>&lt;P&gt;what are the fields showing up in Interesting fields ?&lt;/P&gt;</description>
      <pubDate>Sun, 03 Nov 2019 18:00:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-write-parsing-configuration-for-json-file/m-p/478000#M82036</guid>
      <dc:creator>arjunpkishore5</dc:creator>
      <dc:date>2019-11-03T18:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to write parsing configuration for json file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-write-parsing-configuration-for-json-file/m-p/478001#M82037</link>
      <description>&lt;P&gt;Filename: xxx&lt;BR /&gt;
dest: xxx&lt;BR /&gt;
created_at: xxxx&lt;BR /&gt;
destination_port: null&lt;BR /&gt;
source: xxx&lt;BR /&gt;
username: zxx&lt;/P&gt;

&lt;P&gt;above fields are not populating and time and date field which i have added those only populating&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:52:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-write-parsing-configuration-for-json-file/m-p/478001#M82037</guid>
      <dc:creator>vin02ptl</dc:creator>
      <dc:date>2020-09-30T02:52:03Z</dc:date>
    </item>
  </channel>
</rss>

