I'm using the Microsoft Azure add on for splunk to read from event hub in Azure. I am using Splunk cloud and a heavy fowarder in Azure.
1st. The data showing up is one big field of JSON. I've tried to extract in splunk cloud, but its getting mangled.
2nd. Can i limit this. 75% of my fields are useless and and taking up space.
Can anyone help me out with either issue?
I am using a heavy fwd'r. Splunk support does tell me to use spath. But how do i do this in parsing event hub data? Do i need different addon?