All Apps and Add-ons

Stream App for Stream: field parsing problem when binary src_content or dest_content fields are there

kwchang_splunk
Splunk Employee
Splunk Employee

Dear Stream Experts,

I have a field parsing problem when there are binary(?) src_content or dest_content as following image.
There is src_content and dest_content in _raw, but those fields are not parsed correctly by default.
All fields which appear after the binary src_content or dest_content seem to have problems.

And the web UI is also broken. I selected "List" view but displayed like "Raw" view.

I'm using Splunk App for Stream 6.4.1 on Splunk 6.3.1.
Thank you in advance.

alt text

Tags (1)
0 Karma
1 Solution

vshcherbakov_sp
Splunk Employee
Splunk Employee

hi kwchang,

Seems like Splunk fails to parse this event, despite the event containing properly formatted JSON. I'd recommend opening a ticket in JIRA (SPL project)

View solution in original post

0 Karma

vshcherbakov_sp
Splunk Employee
Splunk Employee

hi kwchang,

Seems like Splunk fails to parse this event, despite the event containing properly formatted JSON. I'd recommend opening a ticket in JIRA (SPL project)

0 Karma
Get Updates on the Splunk Community!

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...

4 Ways the Splunk Community Helps You Prepare for .conf25

.conf25 is right around the corner, and whether you’re a first-time attendee or a seasoned Splunker, the ...