All Apps and Add-ons

Splunk Add-on for Microsoft Cloud Services not parsing .json files from blob correctly

Log_wrangler
Builder

I am using Splunk Add-on for Microsoft Cloud Services to ingest .json logs from blob storage. When I look json log samples in the blob and then compare to what is the index, the events are not parsing correctly.

Is this an Azure problem?

I am not having the issue with s3 files from AWS? using the standard json time parsing conf...

Is there any way to troubleshoot why json parses correct from sources other than Azure, but does not parse correctly from Azure?

I am also having a problem with .gz source files not unzipping from Azure, but files unzip without a problem from AWS?

Please advise.

Thank you

0 Karma

seymouj
New Member

We had the same issue, but it ended up that it was hitting the 1000 max and truncating so we added TRUNCATE = 0 to the props.conf

0 Karma

Log_wrangler
Builder

Thank you for the reply.

BTW the Splunk_TA_Microsoft_Cloud_Services canNOT unzip .gz blobs...

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...