<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Onboarding JSON extract in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Onboarding-JSON-extract/m-p/399814#M8043</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am currently onboarding some data from a different instance of Splunk using a REST API call ... The data produced is JSON and it includes, sourcetype, source, host, _time and _raw.&lt;/P&gt;

&lt;P&gt;Is there any way I can match the details from the JSON extract to the corresponding fields in my local instance (i.e., source, sourcetype and host)?&lt;/P&gt;

&lt;P&gt;How can I also get Splunk to automatically extract the results._raw field? Do I need to create field extraction for all fields?&lt;/P&gt;

&lt;P&gt;the event is currently being onboarded like this:&lt;/P&gt;

&lt;P&gt;7/18/19&lt;BR /&gt;
4:15:00.041 AM&lt;BR /&gt;&lt;BR /&gt;
{   [-] &lt;BR /&gt;
     offset:     7&lt;BR /&gt;&lt;BR /&gt;
     preview:    false&lt;BR /&gt;&lt;BR /&gt;
     result:    {   [-] &lt;BR /&gt;
          _raw:  2019-07-18 02:15:00.041, LONG_RUN_TX="0"&lt;BR /&gt;&lt;BR /&gt;
         _serial:    3&lt;BR /&gt;&lt;BR /&gt;
         _si:   [   [+] &lt;BR /&gt;
        ]&lt;BR /&gt;&lt;BR /&gt;
         _sourcetype:    sql_x&lt;BR /&gt;&lt;BR /&gt;
         _subsecond:     .041&lt;BR /&gt;&lt;BR /&gt;
         _time:  2019-07-18 02:15:00.041 GMT&lt;BR /&gt;&lt;BR /&gt;
         host:   SQL01&lt;BR /&gt;
         source:     sqlx_extract_log&lt;BR /&gt;&lt;BR /&gt;
         sourcetype:     sqlx_extract&lt;BR /&gt;&lt;BR /&gt;
    }&lt;BR /&gt;&lt;BR /&gt;
}&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 01:24:27 GMT</pubDate>
    <dc:creator>RobertEttinger8</dc:creator>
    <dc:date>2020-09-30T01:24:27Z</dc:date>
    <item>
      <title>Onboarding JSON extract</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Onboarding-JSON-extract/m-p/399814#M8043</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am currently onboarding some data from a different instance of Splunk using a REST API call ... The data produced is JSON and it includes, sourcetype, source, host, _time and _raw.&lt;/P&gt;

&lt;P&gt;Is there any way I can match the details from the JSON extract to the corresponding fields in my local instance (i.e., source, sourcetype and host)?&lt;/P&gt;

&lt;P&gt;How can I also get Splunk to automatically extract the results._raw field? Do I need to create field extraction for all fields?&lt;/P&gt;

&lt;P&gt;the event is currently being onboarded like this:&lt;/P&gt;

&lt;P&gt;7/18/19&lt;BR /&gt;
4:15:00.041 AM&lt;BR /&gt;&lt;BR /&gt;
{   [-] &lt;BR /&gt;
     offset:     7&lt;BR /&gt;&lt;BR /&gt;
     preview:    false&lt;BR /&gt;&lt;BR /&gt;
     result:    {   [-] &lt;BR /&gt;
          _raw:  2019-07-18 02:15:00.041, LONG_RUN_TX="0"&lt;BR /&gt;&lt;BR /&gt;
         _serial:    3&lt;BR /&gt;&lt;BR /&gt;
         _si:   [   [+] &lt;BR /&gt;
        ]&lt;BR /&gt;&lt;BR /&gt;
         _sourcetype:    sql_x&lt;BR /&gt;&lt;BR /&gt;
         _subsecond:     .041&lt;BR /&gt;&lt;BR /&gt;
         _time:  2019-07-18 02:15:00.041 GMT&lt;BR /&gt;&lt;BR /&gt;
         host:   SQL01&lt;BR /&gt;
         source:     sqlx_extract_log&lt;BR /&gt;&lt;BR /&gt;
         sourcetype:     sqlx_extract&lt;BR /&gt;&lt;BR /&gt;
    }&lt;BR /&gt;&lt;BR /&gt;
}&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:24:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Onboarding-JSON-extract/m-p/399814#M8043</guid>
      <dc:creator>RobertEttinger8</dc:creator>
      <dc:date>2020-09-30T01:24:27Z</dc:date>
    </item>
  </channel>
</rss>

