All Apps and Add-ons

[osquery App v1.0] Sending results via TCP (Forwarder) in JSON format but Dashboard has no data for visualization

aboggarapu
New Member

Following is the sample data:
{"hostIdentifier": "8AF4BC60-D83D-11DD-B08C-10BF487F7CD8", "created": "2018-07-18T10:22:47.767220", "action": "added", "@timestamp": "2018-07-18T10:22:42", "@version": 1, "log_type": "result", "columns": {"uid": "544", "pid": "30176", "resident_size": "28192768", "sgid": "-1", "suid": "-1", "total_size": "2203514335232", "state": "", "gid": "544", "cwd": "c:\programdata\osquery\osqueryd\osqueryd.exe", "user_time": "1", "nice": "8", "parent": "4504", "start_time": "1531909358", "threads": "26", "euid": "-1", "pgroup": "-1", "path": "c:\programdata\osquery\osqueryd\osqueryd.exe", "system_time": "0", "name": "osqueryd.exe", "cmdline": "c:\programdata\osquery\osqueryd\osqueryd.exe --flagfile osquery.flags", "on_disk": "1", "disk_bytes_written": "", "egid": "-1", "wired_size": "15138816", "root": "c:\programdata\osquery\osqueryd\osqueryd.exe", "disk_bytes_read": ""}, "name": "polylogyx"}

Is there any document on what exactly the format should be? Like the date and time format of "created" attribute.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...