<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: JSON file will not break correctly OR create field extractions in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/JSON-file-will-not-break-correctly-OR-create-field-extractions/m-p/551669#M91558</link>
    <description>&lt;P&gt;This works! Thank you!&lt;/P&gt;</description>
    <pubDate>Fri, 14 May 2021 20:33:05 GMT</pubDate>
    <dc:creator>jason_hotchkiss</dc:creator>
    <dc:date>2021-05-14T20:33:05Z</dc:date>
    <item>
      <title>JSON file will not break correctly OR create field extractions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/JSON-file-will-not-break-correctly-OR-create-field-extractions/m-p/551512#M91533</link>
      <description>&lt;P&gt;inputsHello -&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the following log that will not line break using the traditional ([\r\n)+).&amp;nbsp; Each event splits between:&amp;nbsp;&amp;nbsp;"Properties": {&lt;BR /&gt;&lt;BR /&gt;Here is what I have tried in my Props.conf:&lt;BR /&gt;&lt;BR /&gt;[ mysourcetype ]&lt;BR /&gt;BREAK_ONLY_BEFORE=\"Properties\"\: \{&lt;BR /&gt;LINE_BREAKER=^{&lt;BR /&gt;CHARSET=UTF-8&lt;BR /&gt;DATETIME_CONFIG=CURRENT&lt;BR /&gt;MAX_EVENTS=40000&lt;BR /&gt;SHOULD_LINEMERGE=true&lt;BR /&gt;disabled=false&lt;BR /&gt;pulldown_type=true&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;{ "computers": [ { "Properties": { "haslaps": false, "highvalue": false, "name": "DATA", "domain": "DATA", "objectid": "DATA", "distinguishedname": "DATA", "description": null, "enabled": true, "unconstraineddelegation": false, "serviceprincipalnames": [ "DATA", "DATA", "DATA", "DATA", "DATA", "DATA", "DATA", "DATA" ], "lastlogontimestamp": 1501470433, "pwdlastset": 1500622271, "operatingsystem": "DATA" }, "AllowedToDelegate": [], "AllowedToAct": [], "PrimaryGroupSid": "DATA", "Sessions": [], "LocalAdmins": [], "RemoteDesktopUsers": [], "DcomUsers": [], "PSRemoteUsers": [], "ObjectIdentifier": "DATA", "Aces": [ { "PrincipalSID": "DATA", "PrincipalType": "DATA", "RightName": "DATA", "AceType": "", "IsInherited": DATA }, { "PrincipalSID": "DATA", "PrincipalType": "DATA", "RightName": "DATA", "AceType": "", "IsInherited": false }, { "PrincipalSID": "DATA", "PrincipalType": "DATA", "RightName": "DATA", "AceType": "", "IsInherited": false }, { "PrincipalSID": "DATA", "PrincipalType": "DATA", "RightName": "DATA", "AceType": "", "IsInherited": true }, { "PrincipalSID": "DATA", "PrincipalType": "DATA", "RightName": "DATA", "AceType": "", "IsInherited": true }, { "PrincipalSID": "DATA", "PrincipalType": "DATA", "RightName": "DATA", "AceType": "", "IsInherited": true }, { "PrincipalSID": "DATA", "PrincipalType": "DATA", "RightName": "DATA", "AceType": "", "IsInherited": true }, { "PrincipalSID": "DATA", "PrincipalType": "Unknown", "RightName": "DATA", "AceType": "", "IsInherited": true }, { "PrincipalSID": "DATA", "PrincipalType": "Group", "RightName": "GenericAll", "AceType": "", "IsInherited": true }, { "PrincipalSID": "DATA", "PrincipalType": "Unknown", "RightName": "GenericAll", "AceType": "", "IsInherited": true }, { "PrincipalSID": "DATA", "PrincipalType": "Group", "RightName": "WriteDacl", "AceType": "", "IsInherited": true }, { "PrincipalSID": "DATA", "PrincipalType": "Group", "RightName": "WriteOwner", "AceType": "", "IsInherited": true }, { "PrincipalSID": "DATA", "PrincipalType": "Group", "RightName": "GenericWrite", "AceType": "", "IsInherited": true } ] }, { "Properties": { "haslaps": false, "highvalue": false, "name": "DATA", "domain": "DATA", "objectid": "DATA", "distinguishedname": "DATA", "description": null, "enabled": true, "unconstraineddelegation": false, "serviceprincipalnames": [ "DATA", "DATA", "DATA", "DATA", "DATA", "DATA", "DATA", "DATA", "DATA", "DATA" ], "lastlogontimestamp": 1506599859, "pwdlastset": 1505682659, "operatingsystem": "DATA" }, "AllowedToDelegate": [], "AllowedToAct": [], "PrimaryGroupSid": "DATA", "Sessions": [], "LocalAdmins": [], "RemoteDesktopUsers": [], "DcomUsers": [], "PSRemoteUsers": [], "ObjectIdentifier": "DATA", "Aces": [ { "PrincipalSID": "DATA", "PrincipalType": "Group", "RightName": "Owner", "AceType": "", "IsInherited": false }, { "PrincipalSID": "DATA", "PrincipalType": "Group", "RightName": "GenericAll", "AceType": "", "IsInherited": false }, { "PrincipalSID": "DATA", "PrincipalType": "Group", "RightName": "GenericAll", "AceType": "", "IsInherited": false }, { "PrincipalSID": "DATA", "PrincipalType": "User", "RightName": "GenericAll", "AceType": "", "IsInherited": true }, { "PrincipalSID": "DATA", "PrincipalType": "Group", "RightName": "GenericAll", "AceType": "", "IsInherited": true }, { "PrincipalSID": "DATA", "PrincipalType": "Unknown", "RightName": "GenericAll", "AceType": "", "IsInherited": true }, { "PrincipalSID": "DATA", "PrincipalType": "Group", "RightName": "WriteDacl", "AceType": "", "IsInherited": true }, { "PrincipalSID": "DATA", "PrincipalType": "Group", "RightName": "WriteOwner", "AceType": "", "IsInherited": true }, { "PrincipalSID": "DATA", "PrincipalType": "Group", "RightName": "GenericWrite", "AceType": "", "IsInherited": true } ] &amp;lt;...truncated...&amp;gt;&lt;/P&gt;&lt;P&gt;Any suggestions on how I can get this to break properly &amp;amp; extract the field value pairs?&amp;nbsp; Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 13 May 2021 23:29:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/JSON-file-will-not-break-correctly-OR-create-field-extractions/m-p/551512#M91533</guid>
      <dc:creator>jason_hotchkiss</dc:creator>
      <dc:date>2021-05-13T23:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: JSON file will not break correctly OR create field extractions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/JSON-file-will-not-break-correctly-OR-create-field-extractions/m-p/551530#M91537</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226579"&gt;@jason_hotchkiss&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[YOUR_SOURCETYPE]
SHOULD_LINEMERGE=false
LINE_BREAKER=]}(\,\s){\"Properties
NO_BINARY_CHECK=true
SEDCMD-a=s/{\"computers\": \[//g
SEDCMD-b=s/\]}\]}$/]}/g
TRUNCATE=0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;Kamlesh Vaghela&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 05:30:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/JSON-file-will-not-break-correctly-OR-create-field-extractions/m-p/551530#M91537</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-05-14T05:30:20Z</dc:date>
    </item>
    <item>
      <title>Re: JSON file will not break correctly OR create field extractions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/JSON-file-will-not-break-correctly-OR-create-field-extractions/m-p/551612#M91547</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/127939"&gt;@kamlesh_vaghela&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Hello Kamlesh - that did not work, and I believe that was my fault, as the log format came in wrong.&lt;BR /&gt;&lt;BR /&gt;Here is the regex:&amp;nbsp; &lt;A href="https://regex101.com/r/KkpSIM/1" target="_blank"&gt;https://regex101.com/r/KkpSIM/1&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 14:30:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/JSON-file-will-not-break-correctly-OR-create-field-extractions/m-p/551612#M91547</guid>
      <dc:creator>jason_hotchkiss</dc:creator>
      <dc:date>2021-05-14T14:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: JSON file will not break correctly OR create field extractions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/JSON-file-will-not-break-correctly-OR-create-field-extractions/m-p/551637#M91556</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226579"&gt;@jason_hotchkiss&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ca you please try this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[ &amp;lt;SOURCETYPE NAME&amp;gt; ]
SHOULD_LINEMERGE=false
LINE_BREAKER=\]\n\s{4}}(,\s{5}){\n\s{6}"Properties":
NO_BINARY_CHECK=true
CHARSET=UTF-8
disabled=false
SEDCMD-a=s/{\n\s{2}"computers":\s\[\n\s{4}//g
SEDCMD-b=s/\n\s*//g
SEDCMD-c=s/\]}\]}$/]}/g&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your provided json was not valid. So I have added closing brackets at the end.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check the sample I have used.&lt;/P&gt;&lt;P&gt;&lt;A href="https://regex101.com/r/NFxrJp/1" target="_blank"&gt;https://regex101.com/r/NFxrJp/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV ▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If this reply helps you, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 17:36:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/JSON-file-will-not-break-correctly-OR-create-field-extractions/m-p/551637#M91556</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-05-14T17:36:05Z</dc:date>
    </item>
    <item>
      <title>Re: JSON file will not break correctly OR create field extractions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/JSON-file-will-not-break-correctly-OR-create-field-extractions/m-p/551669#M91558</link>
      <description>&lt;P&gt;This works! Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 20:33:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/JSON-file-will-not-break-correctly-OR-create-field-extractions/m-p/551669#M91558</guid>
      <dc:creator>jason_hotchkiss</dc:creator>
      <dc:date>2021-05-14T20:33:05Z</dc:date>
    </item>
  </channel>
</rss>

