<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Json field not extracted in Splunk DB Connect Input via SQL Server :  using Splunk DB Connect 2.0 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Json-field-not-extracted-in-Splunk-DB-Connect-Input-via-SQL/m-p/393384#M95342</link>
    <description>&lt;P&gt;i have made an INPUT Field through MS SQL SERVER, There is a column in my table which has JSON values, SPLUNK DB Connect is not showing this json value in any of it's event or fields. it is showing only '{' in the JSON field.&lt;BR /&gt;
Please help n guide me to resolve this issue or parse the json key, values in to the new column.&lt;BR /&gt;
Thanks,&lt;/P&gt;</description>
    <pubDate>Mon, 08 Apr 2019 18:17:17 GMT</pubDate>
    <dc:creator>zanjani786</dc:creator>
    <dc:date>2019-04-08T18:17:17Z</dc:date>
    <item>
      <title>Json field not extracted in Splunk DB Connect Input via SQL Server :  using Splunk DB Connect 2.0</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Json-field-not-extracted-in-Splunk-DB-Connect-Input-via-SQL/m-p/393384#M95342</link>
      <description>&lt;P&gt;i have made an INPUT Field through MS SQL SERVER, There is a column in my table which has JSON values, SPLUNK DB Connect is not showing this json value in any of it's event or fields. it is showing only '{' in the JSON field.&lt;BR /&gt;
Please help n guide me to resolve this issue or parse the json key, values in to the new column.&lt;BR /&gt;
Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 18:17:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Json-field-not-extracted-in-Splunk-DB-Connect-Input-via-SQL/m-p/393384#M95342</guid>
      <dc:creator>zanjani786</dc:creator>
      <dc:date>2019-04-08T18:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Json field not extracted in Splunk DB Connect Input via SQL Server :  using Splunk DB Connect 2.0</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Json-field-not-extracted-in-Splunk-DB-Connect-Input-via-SQL/m-p/393385#M95343</link>
      <description>&lt;P&gt;What sourcetype are you using?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2019 12:53:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Json-field-not-extracted-in-Splunk-DB-Connect-Input-via-SQL/m-p/393385#M95343</guid>
      <dc:creator>grittonc</dc:creator>
      <dc:date>2019-04-09T12:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: Json field not extracted in Splunk DB Connect Input via SQL Server :  using Splunk DB Connect 2.0</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Json-field-not-extracted-in-Splunk-DB-Connect-Input-via-SQL/m-p/393386#M95344</link>
      <description>&lt;P&gt;i have connection with MS-SQL Server in my input database. and gave my source type an anonymous name&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 11:00:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Json-field-not-extracted-in-Splunk-DB-Connect-Input-via-SQL/m-p/393386#M95344</guid>
      <dc:creator>zanjani786</dc:creator>
      <dc:date>2019-04-10T11:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: Json field not extracted in Splunk DB Connect Input via SQL Server :  using Splunk DB Connect 2.0</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Json-field-not-extracted-in-Splunk-DB-Connect-Input-via-SQL/m-p/393387#M95345</link>
      <description>&lt;P&gt;Was there ever a solution found for this issue?  I am facing the same problem where the datatype I am returning from the database is of type JSON and being inputed using DBX. In Splunk, however, the field just shows as "{". Example below: &lt;/P&gt;

&lt;P&gt;json_returned_from_db="{"id":1234}"&lt;/P&gt;

&lt;P&gt;The value here is being treated as a String and so the first 2 double quotes encompasess the { and that is what is returned in the field in Splunk.&lt;/P&gt;

&lt;P&gt;I want it to return the result as a JSON type preferably.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:21:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Json-field-not-extracted-in-Splunk-DB-Connect-Input-via-SQL/m-p/393387#M95345</guid>
      <dc:creator>popalzie</dc:creator>
      <dc:date>2020-09-30T04:21:34Z</dc:date>
    </item>
  </channel>
</rss>

