I am using Splunk Add-on for Microsoft Cloud Services to ingest .json logs from blob storage. When I look json log samples in the blob and then compare to what is the index, the events are not parsing correctly.
Is this an Azure problem?
I am not having the issue with s3 files from AWS? using the standard json time parsing conf...
Is there any way to troubleshoot why json parses correct from sources other than Azure, but does not parse correctly from Azure?
I am also having a problem with .gz source files not unzipping from Azure, but files unzip without a problem from AWS?
Please advise.
Thank you
We had the same issue, but it ended up that it was hitting the 1000 max and truncating so we added TRUNCATE = 0 to the props.conf
Thank you for the reply.
BTW the Splunk_TA_Microsoft_Cloud_Services canNOT unzip .gz blobs...