All Apps and Add-ons

Splunk Add-on for Microsoft Cloud Services not parsing .json files from blob correctly

Log_wrangler
Builder

I am using Splunk Add-on for Microsoft Cloud Services to ingest .json logs from blob storage. When I look json log samples in the blob and then compare to what is the index, the events are not parsing correctly.

Is this an Azure problem?

I am not having the issue with s3 files from AWS? using the standard json time parsing conf...

Is there any way to troubleshoot why json parses correct from sources other than Azure, but does not parse correctly from Azure?

I am also having a problem with .gz source files not unzipping from Azure, but files unzip without a problem from AWS?

Please advise.

Thank you

0 Karma

seymouj
New Member

We had the same issue, but it ended up that it was hitting the 1000 max and truncating so we added TRUNCATE = 0 to the props.conf

0 Karma

Log_wrangler
Builder

Thank you for the reply.

BTW the Splunk_TA_Microsoft_Cloud_Services canNOT unzip .gz blobs...

0 Karma
Get Updates on the Splunk Community!

Happy CX Day to our Community Superheroes!

Happy 10th Birthday CX Day!What is CX Day? It’s a global celebration recognizing innovation and success in the ...

Check out This Month’s Brand new Splunk Lantern Articles

Splunk Lantern is a customer success center providing advice from Splunk experts on valuable data insights, ...

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...