<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: JSON - different output in the data preview and monitored files in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/JSON-different-output-in-the-data-preview-and-monitored-files/m-p/454041#M96455</link>
    <description>&lt;P&gt;the client machine has an universal forwarded installed, and the inputs.conf has the following&lt;/P&gt;

&lt;P&gt;[monitor://X:\Logs\Website]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
index = sandbox_webservers_logs_errors&lt;BR /&gt;
whitelist = errors&lt;BR /&gt;
sourcetype = ErrorLog_json&lt;/P&gt;

&lt;P&gt;the index database shows 177 events which is correct then when i go to the search bar and i type the following it only give 1 line&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/268593-2-5-2019-5-15-34-pm.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;index="sandbox_webservers_logs_errors" sourcetype="ErrorLog_json"&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 23:10:00 GMT</pubDate>
    <dc:creator>abilis</dc:creator>
    <dc:date>2020-09-29T23:10:00Z</dc:date>
    <item>
      <title>JSON - different output in the data preview and monitored files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/JSON-different-output-in-the-data-preview-and-monitored-files/m-p/454039#M96453</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;

&lt;P&gt;does anyone know why when i use data preview or a manually upload the file and apply a custom json sourcetype everything seems to be fine and splunk is recognizing an event per line, but when i monitor a file from a remote server i can see in the index the exact number of event that i have in the remote file but the search only show 1 event &lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/268592-2-5-2019-4-32-39-pm.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;in the remote inputs.conf file i have specified the name of the sourcetype i want to use&lt;/P&gt;

&lt;P&gt;[monitor://X:\Logs\Website]&lt;BR /&gt;
 disabled = false&lt;BR /&gt;
 index = sandbox_webservers_logs_errors&lt;BR /&gt;
 whitelist = errors&lt;BR /&gt;&lt;BR /&gt;
 sourcetype = ErrorLog_json&lt;/P&gt;

&lt;P&gt;thanks for your help...&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:09:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/JSON-different-output-in-the-data-preview-and-monitored-files/m-p/454039#M96453</guid>
      <dc:creator>abilis</dc:creator>
      <dc:date>2020-09-29T23:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: JSON - different output in the data preview and monitored files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/JSON-different-output-in-the-data-preview-and-monitored-files/m-p/454040#M96454</link>
      <description>&lt;P&gt;If your data is going through a heavy forwarder before it gets to your indexer, then you will need to put your &lt;CODE&gt;[ErrorLog_json]&lt;/CODE&gt; sourcetype stanza on that heavy forwarder.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2019 21:41:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/JSON-different-output-in-the-data-preview-and-monitored-files/m-p/454040#M96454</guid>
      <dc:creator>chrisyounger</dc:creator>
      <dc:date>2019-02-05T21:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: JSON - different output in the data preview and monitored files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/JSON-different-output-in-the-data-preview-and-monitored-files/m-p/454041#M96455</link>
      <description>&lt;P&gt;the client machine has an universal forwarded installed, and the inputs.conf has the following&lt;/P&gt;

&lt;P&gt;[monitor://X:\Logs\Website]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
index = sandbox_webservers_logs_errors&lt;BR /&gt;
whitelist = errors&lt;BR /&gt;
sourcetype = ErrorLog_json&lt;/P&gt;

&lt;P&gt;the index database shows 177 events which is correct then when i go to the search bar and i type the following it only give 1 line&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/268593-2-5-2019-5-15-34-pm.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;index="sandbox_webservers_logs_errors" sourcetype="ErrorLog_json"&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:10:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/JSON-different-output-in-the-data-preview-and-monitored-files/m-p/454041#M96455</guid>
      <dc:creator>abilis</dc:creator>
      <dc:date>2020-09-29T23:10:00Z</dc:date>
    </item>
  </channel>
</rss>

