<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic json kvm_mode and additional transforms in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/json-kvm-mode-and-additional-transforms/m-p/557416#M92263</link>
    <description>&lt;P&gt;Please confirm/deny something for me because it's not clear from the docs.&lt;/P&gt;&lt;P&gt;Let's assume I have events containing both "unstructured" data and json. Something similar to the ones from &lt;A href="https://community.splunk.com/t5/Getting-Data-In/JSON-transformations/m-p/370127#M67168" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/JSON-transformations/m-p/370127#M67168&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Dec 1 22:29:42 127.0.0.1 1 2017-12-01 LOGSERVER 1292 - - {"event_type":"type_here","ipv4":"127.0.0.1","hostname":"pc_name.local","occured":"01-Dec-2017 22:24:34"}&lt;/P&gt;&lt;P&gt;If I set KV_MODE=json, I assume the fields from the json part should get parsed automaticaly. But what about the rest of the message? Can I still apply transforms to get additional fields parsed from the event?&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jun 2021 12:24:48 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2021-06-28T12:24:48Z</dc:date>
    <item>
      <title>json kvm_mode and additional transforms</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/json-kvm-mode-and-additional-transforms/m-p/557416#M92263</link>
      <description>&lt;P&gt;Please confirm/deny something for me because it's not clear from the docs.&lt;/P&gt;&lt;P&gt;Let's assume I have events containing both "unstructured" data and json. Something similar to the ones from &lt;A href="https://community.splunk.com/t5/Getting-Data-In/JSON-transformations/m-p/370127#M67168" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/JSON-transformations/m-p/370127#M67168&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Dec 1 22:29:42 127.0.0.1 1 2017-12-01 LOGSERVER 1292 - - {"event_type":"type_here","ipv4":"127.0.0.1","hostname":"pc_name.local","occured":"01-Dec-2017 22:24:34"}&lt;/P&gt;&lt;P&gt;If I set KV_MODE=json, I assume the fields from the json part should get parsed automaticaly. But what about the rest of the message? Can I still apply transforms to get additional fields parsed from the event?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 12:24:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/json-kvm-mode-and-additional-transforms/m-p/557416#M92263</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-06-28T12:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: json kvm_mode and additional transforms</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/json-kvm-mode-and-additional-transforms/m-p/557453#M92268</link>
      <description>&lt;P&gt;Furthermore, do I understand properly that KV_MODE=json would be applied in search-time. So if I want to additionaly manipulate - for example - time and host which are indexed fields I'd have to make an app affecting ingest-time as well? So I'd need to have both search-time configuration on search-head(s) and ingest-time extractions on heavy-forwarder(s)?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 16:19:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/json-kvm-mode-and-additional-transforms/m-p/557453#M92268</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-06-28T16:19:30Z</dc:date>
    </item>
  </channel>
</rss>

