All Apps and Add-ons

Stream App for Stream: field parsing problem when binary src_content or dest_content fields are there

kwchang_splunk
Splunk Employee
Splunk Employee

Dear Stream Experts,

I have a field parsing problem when there are binary(?) src_content or dest_content as following image.
There is src_content and dest_content in _raw, but those fields are not parsed correctly by default.
All fields which appear after the binary src_content or dest_content seem to have problems.

And the web UI is also broken. I selected "List" view but displayed like "Raw" view.

I'm using Splunk App for Stream 6.4.1 on Splunk 6.3.1.
Thank you in advance.

alt text

Tags (1)
0 Karma
1 Solution

vshcherbakov_sp
Splunk Employee
Splunk Employee

hi kwchang,

Seems like Splunk fails to parse this event, despite the event containing properly formatted JSON. I'd recommend opening a ticket in JIRA (SPL project)

View solution in original post

0 Karma

vshcherbakov_sp
Splunk Employee
Splunk Employee

hi kwchang,

Seems like Splunk fails to parse this event, despite the event containing properly formatted JSON. I'd recommend opening a ticket in JIRA (SPL project)

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...