<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to export events as JSON format? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-export-events-as-JSON-format/m-p/624396#M217090</link>
    <description>&lt;P&gt;Have you tried using "KV_MODE = json" in props.conf where the corresponding Sourcetype is defined?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[your_sourcetype]
KV_MODE = json
#your other settings for the sourcetype:&lt;/LI-CODE&gt;</description>
    <pubDate>Thu, 15 Dec 2022 15:46:20 GMT</pubDate>
    <dc:creator>FelixLeh</dc:creator>
    <dc:date>2022-12-15T15:46:20Z</dc:date>
    <item>
      <title>How to export events as JSON format?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-export-events-as-JSON-format/m-p/624367#M217089</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I am trying to export events in JSON format, and I am able to do it, and getting events like the one below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{"preview":false,"result":{"_raw":"{\"tomLogs\":[{\"component\":\"tom\"}]}}}
{"preview":false,"result":{"_raw":"{\"tomLogs\":[{\"component\":\"tom\"}]}}}
{"preview":false,"result":{"_raw":"{\"tomLogs\":[{\"component\":\"tom\"}]}}}&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But the My expectation of having these events in an array with commas separated like the below format.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[
{"preview":false,"result":{"_raw":"{\"tomLogs\":[{\"component\":\"tom\"}]}}},
{"preview":false,"result":{"_raw":"{\"tomLogs\":[{\"component\":\"tom\"}]}}},
{"preview":false,"result":{"_raw":"{\"tomLogs\":[{\"component\":\"tom\"}]}}}
]&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please provide some references that can help to export events in the expected format.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 14:48:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-export-events-as-JSON-format/m-p/624367#M217089</guid>
      <dc:creator>sutom</dc:creator>
      <dc:date>2022-12-15T14:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to export events as JSON format?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-export-events-as-JSON-format/m-p/624396#M217090</link>
      <description>&lt;P&gt;Have you tried using "KV_MODE = json" in props.conf where the corresponding Sourcetype is defined?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[your_sourcetype]
KV_MODE = json
#your other settings for the sourcetype:&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 15 Dec 2022 15:46:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-export-events-as-JSON-format/m-p/624396#M217090</guid>
      <dc:creator>FelixLeh</dc:creator>
      <dc:date>2022-12-15T15:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to export events as JSON format?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-export-events-as-JSON-format/m-p/624505#M217115</link>
      <description>&lt;P&gt;The question is really "how to export events as JSON array." &amp;nbsp;Is this correct? &amp;nbsp;The result you got are a sequence of perfectly correct JSON events.&lt;/P&gt;&lt;P&gt;If you want all those events exported to one big array, why not put all events in one big array? &amp;nbsp;Like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats values(_raw) as jumbo_raw&lt;/LI-CODE&gt;&lt;P&gt;The export will then look like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{"preview":false,"result":{"_raw":[
{"tomLogs":[{"component":"tom"}]},
{"tomLogs":[{"component":"tom"}]},
{"tomLogs":[{"component":"tom"}]}
]}
}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Will this array do? Otherwise you can write a simple script to convert a series of JSON objects into a JSON array.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 06:37:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-export-events-as-JSON-format/m-p/624505#M217115</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-12-16T06:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to export events as JSON format?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-export-events-as-JSON-format/m-p/624584#M217129</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232795"&gt;@sutom&lt;/a&gt;&amp;nbsp;- I would say the export is correct, add the [ (square brackets) and , (commas) in the exported file manually by regex replace in any advance text/code editor.&lt;/P&gt;&lt;P&gt;This would be the simplest option to what you want to achive. You can also write a small python script to do that we well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!!&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 16:14:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-export-events-as-JSON-format/m-p/624584#M217129</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-12-16T16:14:10Z</dc:date>
    </item>
  </channel>
</rss>

