All Apps and Add-ons

Splunk Add-on for Microsoft Cloud Services not parsing .json files from blob correctly

Log_wrangler
Builder

I am using Splunk Add-on for Microsoft Cloud Services to ingest .json logs from blob storage. When I look json log samples in the blob and then compare to what is the index, the events are not parsing correctly.

Is this an Azure problem?

I am not having the issue with s3 files from AWS? using the standard json time parsing conf...

Is there any way to troubleshoot why json parses correct from sources other than Azure, but does not parse correctly from Azure?

I am also having a problem with .gz source files not unzipping from Azure, but files unzip without a problem from AWS?

Please advise.

Thank you

0 Karma

seymouj
New Member

We had the same issue, but it ended up that it was hitting the 1000 max and truncating so we added TRUNCATE = 0 to the props.conf

0 Karma

Log_wrangler
Builder

Thank you for the reply.

BTW the Splunk_TA_Microsoft_Cloud_Services canNOT unzip .gz blobs...

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...