<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic json SED problem in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/json-SED-problem/m-p/558306#M92372</link>
    <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;I am having json logs which I on-boarded to Splunk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{"body":{"records": {"time": "2020-12-20T13:28:50.2164144Z","MachineGroup": "Windows 10", "Timestamp": "2020-12-20T13:27:18.6679858Z", "DeviceName": "3242d4e4.dc.democorp.com", "ReportId": 306737}}},"x-opt-sequence-number":159959006,"x-opt-offset":"2713650553292728","x-opt-enqueued-time":1624195823422}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to remove everything after "}}}" with SEDCMD and my props.conf is below-mentioned&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[json_log]
LINE_BREAKER = ([\r\n]+)
NO_BINARY_CHECK = true
category = Custom
disabled = false
INDEXED_EXTRACTIONS = json
KV_MODE = none
DATETIME_CONFIG = CURRENT
TRUNCATE = 0
SEDCMD-unwantedfields=s/\}\}\}(.*)/g&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fields are not in raw logs, however when expending details can see the field values&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="General_Talos_0-1625487024842.png" style="width: 479px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14939i18440DB860E38400/image-dimensions/479x73?v=v2" width="479" height="73" role="button" title="General_Talos_0-1625487024842.png" alt="General_Talos_0-1625487024842.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any suggestion, what I am doing wrong ?&lt;/P&gt;&lt;P&gt;&lt;A href="https://regex101.com/r/btYSah/1" target="_blank"&gt;https://regex101.com/r/btYSah/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="General_Talos_0-1625487274300.png" style="width: 523px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14940i9A7B5B8EE045B9CA/image-dimensions/523x408?v=v2" width="523" height="408" role="button" title="General_Talos_0-1625487274300.png" alt="General_Talos_0-1625487274300.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 12:15:06 GMT</pubDate>
    <dc:creator>General_Talos</dc:creator>
    <dc:date>2021-07-05T12:15:06Z</dc:date>
    <item>
      <title>json SED problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/json-SED-problem/m-p/558306#M92372</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;I am having json logs which I on-boarded to Splunk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{"body":{"records": {"time": "2020-12-20T13:28:50.2164144Z","MachineGroup": "Windows 10", "Timestamp": "2020-12-20T13:27:18.6679858Z", "DeviceName": "3242d4e4.dc.democorp.com", "ReportId": 306737}}},"x-opt-sequence-number":159959006,"x-opt-offset":"2713650553292728","x-opt-enqueued-time":1624195823422}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to remove everything after "}}}" with SEDCMD and my props.conf is below-mentioned&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[json_log]
LINE_BREAKER = ([\r\n]+)
NO_BINARY_CHECK = true
category = Custom
disabled = false
INDEXED_EXTRACTIONS = json
KV_MODE = none
DATETIME_CONFIG = CURRENT
TRUNCATE = 0
SEDCMD-unwantedfields=s/\}\}\}(.*)/g&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fields are not in raw logs, however when expending details can see the field values&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="General_Talos_0-1625487024842.png" style="width: 479px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14939i18440DB860E38400/image-dimensions/479x73?v=v2" width="479" height="73" role="button" title="General_Talos_0-1625487024842.png" alt="General_Talos_0-1625487024842.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any suggestion, what I am doing wrong ?&lt;/P&gt;&lt;P&gt;&lt;A href="https://regex101.com/r/btYSah/1" target="_blank"&gt;https://regex101.com/r/btYSah/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="General_Talos_0-1625487274300.png" style="width: 523px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14940i9A7B5B8EE045B9CA/image-dimensions/523x408?v=v2" width="523" height="408" role="button" title="General_Talos_0-1625487274300.png" alt="General_Talos_0-1625487274300.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 12:15:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/json-SED-problem/m-p/558306#M92372</guid>
      <dc:creator>General_Talos</dc:creator>
      <dc:date>2021-07-05T12:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: json SED problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/json-SED-problem/m-p/558320#M92376</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230358"&gt;@General_Talos&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[json_log]
SHOULD_LINEMERGE=true
LINE_BREAKER=([\r\n]+)
NO_BINARY_CHECK=true
SEDCMD-unwantedfields=s/\}\}\}(.*)/}}}/g&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 14:51:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/json-SED-problem/m-p/558320#M92376</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-07-05T14:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: json SED problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/json-SED-problem/m-p/558332#M92377</link>
      <description>&lt;P&gt;Thanks @kamlesh&lt;/P&gt;&lt;P&gt;Minor changes, resulted in required result.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;SEDCMD-unwantedfields=s/\}\}\}(.*)\}/g&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 16:57:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/json-SED-problem/m-p/558332#M92377</guid>
      <dc:creator>General_Talos</dc:creator>
      <dc:date>2021-07-05T16:57:18Z</dc:date>
    </item>
  </channel>
</rss>

