<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk search does not return event data when there is multiple json in same event in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-does-not-return-event-data-when-there-is-multiple/m-p/393968#M114500</link>
    <description>&lt;P&gt;I have a created a splunk alert when there is a failure occurs. I have query as follows:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=* source=*** |spath path=TestLog.TestFailureLog.appName output=APPNAME|spath path=TestLog.TestFailureLog.eventType output=EVENTTYPE|spath path=TestLog.TestFailureLog.payload.level output=LEVEL|spath path=TestLog.TestFailureLog.payload.failureCount output=FAILURECOUNT|spath path=TestLog.TestFailureLog.payload.errorDescription output=ERRORDESCRIPTION|where APPNAME!="" and LEVEL="ERROR"|table APPNAME,EVENTTYPE,LEVEL,FAILURECOUNT,ERRORDESCRIPTION
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It is working fine when I have single jsonobject per event in the log . For eg:&lt;BR /&gt;
If I have Data like below:&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6561iDE8DD7A36717E815/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;But, if in case I have both success and failure log in the same event, that particular event is vomited and it returns all the remaining failure logs.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6562i1E97022E7F0EE0D0/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Can Anyone please suggest me the solution for it.&lt;/P&gt;</description>
    <pubDate>Thu, 21 Feb 2019 18:35:15 GMT</pubDate>
    <dc:creator>karthi25</dc:creator>
    <dc:date>2019-02-21T18:35:15Z</dc:date>
    <item>
      <title>Splunk search does not return event data when there is multiple json in same event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-does-not-return-event-data-when-there-is-multiple/m-p/393968#M114500</link>
      <description>&lt;P&gt;I have a created a splunk alert when there is a failure occurs. I have query as follows:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=* source=*** |spath path=TestLog.TestFailureLog.appName output=APPNAME|spath path=TestLog.TestFailureLog.eventType output=EVENTTYPE|spath path=TestLog.TestFailureLog.payload.level output=LEVEL|spath path=TestLog.TestFailureLog.payload.failureCount output=FAILURECOUNT|spath path=TestLog.TestFailureLog.payload.errorDescription output=ERRORDESCRIPTION|where APPNAME!="" and LEVEL="ERROR"|table APPNAME,EVENTTYPE,LEVEL,FAILURECOUNT,ERRORDESCRIPTION
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It is working fine when I have single jsonobject per event in the log . For eg:&lt;BR /&gt;
If I have Data like below:&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6561iDE8DD7A36717E815/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;But, if in case I have both success and failure log in the same event, that particular event is vomited and it returns all the remaining failure logs.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6562i1E97022E7F0EE0D0/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Can Anyone please suggest me the solution for it.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Feb 2019 18:35:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-does-not-return-event-data-when-there-is-multiple/m-p/393968#M114500</guid>
      <dc:creator>karthi25</dc:creator>
      <dc:date>2019-02-21T18:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search does not return event data when there is multiple json in same event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-does-not-return-event-data-when-there-is-multiple/m-p/393969#M114501</link>
      <description>&lt;P&gt;@karthi25&lt;BR /&gt;
It seems your given JSON is invalid. Can you please share actual event having multiple logs? Don't beautify JSON share it as it is.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Feb 2019 12:44:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-does-not-return-event-data-when-there-is-multiple/m-p/393969#M114501</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2019-02-23T12:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search does not return event data when there is multiple json in same event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-does-not-return-event-data-when-there-is-multiple/m-p/393970#M114502</link>
      <description>&lt;P&gt;@kamlesh_vaghela Thanks for your response.I have updated my question. Please look in to it. Kindly let me know, if you found anything. Since, these logs are from other sources, I can't change the logging format .&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2019 10:32:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-does-not-return-event-data-when-there-is-multiple/m-p/393970#M114502</guid>
      <dc:creator>karthi25</dc:creator>
      <dc:date>2019-02-25T10:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search does not return event data when there is multiple json in same event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-does-not-return-event-data-when-there-is-multiple/m-p/393971#M114503</link>
      <description>&lt;P&gt;Thanks, @karthi25 for updating question. Is it ok if you share 2nd event in text format? So we can work on those samples to help you. Use Code Sample ( 5th icon in above panel) for same. update confidential values with a dummy value. &lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 13:39:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-does-not-return-event-data-when-there-is-multiple/m-p/393971#M114503</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2019-02-26T13:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search does not return event data when there is multiple json in same event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-does-not-return-event-data-when-there-is-multiple/m-p/393972#M114504</link>
      <description>&lt;P&gt;@kamlesh_vaghela  Sure. Please find the text format for the 2nd event below:&lt;/P&gt;

&lt;P&gt;{&lt;BR /&gt;
  "TestSplunkLog" : {&lt;BR /&gt;
    "TestSuccessLog" : {&lt;BR /&gt;
      "appName" : "Testsscount",&lt;BR /&gt;
      "eventType" : "event1",&lt;BR /&gt;
      "payload" : {&lt;BR /&gt;
        "level" : "INFO",&lt;BR /&gt;
        "startTime" : "2019-02-21 18:02:58",&lt;BR /&gt;
        "sourceCount" : 0,&lt;BR /&gt;
        "successCount" : 0,&lt;BR /&gt;
        "duplicateCount" : 0,&lt;BR /&gt;
        "publishedCount" : 0,&lt;BR /&gt;
        "endTime" : "2019-02-21 18:02:59"&lt;BR /&gt;
      }&lt;BR /&gt;
    }&lt;BR /&gt;
  }&lt;BR /&gt;
}&lt;BR /&gt;
{&lt;BR /&gt;
  "TestSplunkLog" : {&lt;BR /&gt;
    "TestFailureLog" : {&lt;BR /&gt;
      "appName" : "Testsscount",&lt;BR /&gt;
      "eventType" : "event1",&lt;BR /&gt;
      "payload" : {&lt;BR /&gt;
        "level" : "ERROR",&lt;BR /&gt;
        "startTime" : "2019-02-21 18:02:58",&lt;BR /&gt;
        "failureCount" : 0,&lt;BR /&gt;
        "errorCode" : 17002,&lt;BR /&gt;
        "errorDescription" : "IO Error: Unknown host specified ",&lt;BR /&gt;
        "failureIdList" : [ ],&lt;BR /&gt;
        "endTime" : "2019-02-21 18:02:59"&lt;BR /&gt;
      }&lt;BR /&gt;
    }&lt;BR /&gt;
  }&lt;BR /&gt;
}&lt;BR /&gt;
Collapse&lt;BR /&gt;
host =  *** source =*** sourcetype =***&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 05:34:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-does-not-return-event-data-when-there-is-multiple/m-p/393972#M114504</guid>
      <dc:creator>karthi25</dc:creator>
      <dc:date>2019-02-27T05:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search does not return event data when there is multiple json in same event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-does-not-return-event-data-when-there-is-multiple/m-p/393973#M114505</link>
      <description>&lt;P&gt;@karthi25&lt;/P&gt;

&lt;P&gt;Can you please try below search? I have split events as expected. For that, I have added &lt;CODE&gt;||&lt;/CODE&gt; using replace tp split events.  Here Might be you need to change values&lt;CODE&gt;}\n{&lt;/CODE&gt; to &lt;CODE&gt;your_brackates&lt;/CODE&gt;.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;&amp;lt;YOUR_host_source_sourcetype&amp;gt;&amp;gt;
| fields _time _raw
| eval data = replace(_raw,"}\n{","}||{") 
| eval data = split(data,"||") 
| mvexpand data | eval _raw=data | kv | table TestSplunkLog.*
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 08:43:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-does-not-return-event-data-when-there-is-multiple/m-p/393973#M114505</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2019-02-28T08:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search does not return event data when there is multiple json in same event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-does-not-return-event-data-when-there-is-multiple/m-p/393974#M114506</link>
      <description>&lt;P&gt;@kamlesh_vaghela finally it works, Thanks a lot.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 11:44:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-does-not-return-event-data-when-there-is-multiple/m-p/393974#M114506</guid>
      <dc:creator>karthi25</dc:creator>
      <dc:date>2019-02-28T11:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search does not return event data when there is multiple json in same event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-does-not-return-event-data-when-there-is-multiple/m-p/393975#M114507</link>
      <description>&lt;P&gt;@karthi25 &lt;BR /&gt;
Great. &lt;/P&gt;

&lt;P&gt;Please upvote and accept this answer to close this question.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Happy Splunking&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 11:49:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-does-not-return-event-data-when-there-is-multiple/m-p/393975#M114507</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2019-02-28T11:49:38Z</dc:date>
    </item>
  </channel>
</rss>

