<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: JSON with Timestamp (syslog) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/JSON-with-Timestamp-syslog/m-p/513900#M87125</link>
    <description>&lt;P&gt;Putting the props.conf on the indexer fixed my issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Aug 2020 12:46:55 GMT</pubDate>
    <dc:creator>poisar</dc:creator>
    <dc:date>2020-08-13T12:46:55Z</dc:date>
    <item>
      <title>JSON with Timestamp (syslog)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/JSON-with-Timestamp-syslog/m-p/513877#M87123</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;i am getting the following json via syslog and i ingest it to splunk.&lt;/P&gt;&lt;P&gt;Aug 13 12:45:40 10.200.7.200 {"Status": "Failed", "Received": "2020-08-13T10:45:07.2887421", "ToIP": null, "StartDate": "2020-08-13T10:44:39.530583Z", "Index": 2, "EndDate": "2020-08-13T10:45:39.530583Z", "FromIP": "2603:10a6:803:67::17"}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i want to extract the json data. So i created a new app on my searchhead with a props.conf for my custom sourcetype:&lt;/P&gt;&lt;P&gt;[security:type]&lt;BR /&gt;TIME_PREFIX = "Received":\s*"&lt;BR /&gt;# SEDCMD-strip_prefix = s/^[^{]+//g&lt;BR /&gt;SEDCMD-StripHeader = s/^[^\{]+//&lt;BR /&gt;INDEXED_EXTRACTIONS=JSON&lt;BR /&gt;KV_MODE=json&lt;BR /&gt;TZ = UTC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;still it doesnt extract the json data. Can someone help me out?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance!&lt;/P&gt;&lt;P&gt;Andreas&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 10:59:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/JSON-with-Timestamp-syslog/m-p/513877#M87123</guid>
      <dc:creator>poisar</dc:creator>
      <dc:date>2020-08-13T10:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: JSON with Timestamp (syslog)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/JSON-with-Timestamp-syslog/m-p/513900#M87125</link>
      <description>&lt;P&gt;Putting the props.conf on the indexer fixed my issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 12:46:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/JSON-with-Timestamp-syslog/m-p/513900#M87125</guid>
      <dc:creator>poisar</dc:creator>
      <dc:date>2020-08-13T12:46:55Z</dc:date>
    </item>
  </channel>
</rss>

