<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to index data from zigbee2mqtt? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-index-data-from-zigbee2mqtt/m-p/658342#M227408</link>
    <description>&lt;P&gt;Those props.conf settings should be on a heavy forwarder and/or an indexer.&amp;nbsp; They do no good on a universal forwarder.&lt;/P&gt;&lt;P&gt;If the event is not pure and correct JSON then the INDEXED_EXTRACTIONS=JSON and KV_MODE=_json settings won't work.&lt;/P&gt;</description>
    <pubDate>Thu, 21 Sep 2023 19:26:20 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-09-21T19:26:20Z</dc:date>
    <item>
      <title>How to index data from zigbee2mqtt?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-index-data-from-zigbee2mqtt/m-p/658176#M227356</link>
      <description>&lt;P&gt;can't figure out how to indexing my data from zigbee2mgtt.&amp;nbsp; The logs are exported from Home assistance via syslog, as Json.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have tried various settings in props on the forwarder.&lt;BR /&gt;&lt;SPAN&gt;&lt;BR /&gt;Current setting:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;[zigbee2mqtt]&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;DATETIME_CONFIG =&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;INDEXED_EXTRACTIONS = JSON&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;category = structured&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;NO_BINARY_CHECK = true&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;TIMESTAMP_FIELDS = timestamp&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;LINE_BREAKER = ([\r\n]+)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;disabled = false&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;pulldown_type = true&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;And on the search:&lt;/P&gt;
&lt;P&gt;Current:&lt;BR /&gt;&lt;EM&gt;[zigbee2mqtt]&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;KV_MODE = JSON&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;And this is how the data appears in the log.&amp;nbsp; for me it looks like some kind mix, not just JSON data.&lt;/P&gt;
&lt;DIV&gt;&lt;EM&gt;Sep 20 19:13:19 linsrv 1 2023-09-20T17:13:19.941+02:00 localhost Zigbee2MQTT - - - MQTT publish: topic 'zigbee2mqtt/P001', payload '{"auto_off":null,"button_lock":null,"consumer_connected":true,"consumption":7.82,"current":0,"device_temperature":25,"energy":7.82,"led_disabled_night":null,"linkquality":255,"overload_protection":null,"power":0,"power_outage_count":3,"power_outage_memory":null,"state":"OFF","update":{"installed_version":41,"latest_version":32,"state":"idle"},"update_available":false,"voltage":234}'/n&lt;/EM&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;EM&gt;host = linsrv index = zigbee source = /disk1/syslog/in/linsrv/2023-09-20/messages.log sourcetype = zigbee2mqtt&lt;/EM&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;EM&gt;Sep 20 19:08:13 linsrv06.hemdata.hemdata.se 1 2023-09-20T17:08:13.988+02:00 localhost Zigbee2MQTT - - - MQTT publish: topic 'zigbee2mqtt/P002', payload '{"auto_off":null,"button_lock":null,"consumer_connected":true,"consumption":2.58,"current":0,"device_temperature":23,"energy":2.58,"led_disabled_night":null,"linkquality":255,"overload_protection":null,"power":0,"power_outage_count":0,"power_outage_memory":null,"state":"OFF","update":{"installed_version":41,"latest_version":32,"state":"idle"},"update_available":false,"voltage":229}'/n&lt;/EM&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;EM&gt;host = linsrv index = zigbee source = /disk1/syslog/in/linsrv/2023-09-20/messages.log sourcetype = zigbee2mqtt&lt;/EM&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;EM&gt;Sep 20 19:08:13 linsrv 1 2023-09-20T17:08:13.968+02:00 localhost Zigbee2MQTT - - - MQTT publish: topic 'zigbee2mqtt/P001', payload '{"auto_off":null,"button_lock":null,"consumer_connected":true,"consumption":7.82,"current":0,"device_temperature":25,"energy":7.82,"led_disabled_night":null,"linkquality":255,"overload_protection":null,"power":0,"power_outage_count":3,"power_outage_memory":null,"state":"OFF","update":{"installed_version":41,"latest_version":32,"state":"idle"},"update_available":false,"voltage":234}'/n&lt;/EM&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;EM&gt;host = linsrv index = zigbee source = /disk1/syslog/in/linsrv/2023-09-20/messages.logsourcetype = zigbee2mqtt&lt;/EM&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;EM&gt;Sep 20 19:08:06 linsrv 1 2023-09-20T17:08:06.199+02:00 localhost Zigbee2MQTT - - - MQTT publish: topic 'zigbee2mqtt/P002', payload '{"auto_off":null,"button_lock":null,"consumer_connected":true,"consumption":2.58,"current":0,"device_temperature":23,"energy":2.58,"led_disabled_night":null,"linkquality":255,"overload_protection":null,"power":0,"power_outage_count":0,"power_outage_memory":null,"state":"OFF","update":{"installed_version":41,"latest_version":32,"state":"idle"},"update_available":false,"voltage":229}'/n&lt;/EM&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;EM&gt;host = linsrv index = zigbee source = /disk1/syslog/in/linsrv/2023-09-20/messages.log sourcetype = zigbee2mqtt&lt;/EM&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 20:04:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-index-data-from-zigbee2mqtt/m-p/658176#M227356</guid>
      <dc:creator>swejoos</dc:creator>
      <dc:date>2023-09-20T20:04:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to index data from zigbee2mqtt?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-index-data-from-zigbee2mqtt/m-p/658342#M227408</link>
      <description>&lt;P&gt;Those props.conf settings should be on a heavy forwarder and/or an indexer.&amp;nbsp; They do no good on a universal forwarder.&lt;/P&gt;&lt;P&gt;If the event is not pure and correct JSON then the INDEXED_EXTRACTIONS=JSON and KV_MODE=_json settings won't work.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 19:26:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-index-data-from-zigbee2mqtt/m-p/658342#M227408</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-09-21T19:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to index data from zigbee2mqtt?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-index-data-from-zigbee2mqtt/m-p/658522#M227466</link>
      <description>&lt;P&gt;Ok, Thanks.&lt;/P&gt;&lt;P&gt;So I should move all config to the search instead.&lt;/P&gt;&lt;P&gt;I have now tried that and the result seems to be the same, still index.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Sep 2023 18:52:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-index-data-from-zigbee2mqtt/m-p/658522#M227466</guid>
      <dc:creator>swejoos</dc:creator>
      <dc:date>2023-09-24T18:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to index data from zigbee2mqtt?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-index-data-from-zigbee2mqtt/m-p/658534#M227467</link>
      <description>&lt;P&gt;As stated in my original reply, the settings go on indexers and/or heavy forwarders.&amp;nbsp; You can put them on search heads, but they won't do any good.&amp;nbsp; Unless, that is, you have a standalone system (combined indexer and search head).&lt;/P&gt;</description>
      <pubDate>Sun, 24 Sep 2023 23:11:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-index-data-from-zigbee2mqtt/m-p/658534#M227467</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-09-24T23:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to index data from zigbee2mqtt?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-index-data-from-zigbee2mqtt/m-p/658961#M227579</link>
      <description>&lt;P&gt;ok. sorry,&lt;/P&gt;&lt;P&gt;But yes I have a combined index/search head, and a separate universal forwarder.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 13:08:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-index-data-from-zigbee2mqtt/m-p/658961#M227579</guid>
      <dc:creator>swejoos</dc:creator>
      <dc:date>2023-09-28T13:08:58Z</dc:date>
    </item>
  </channel>
</rss>

