Archive
Highlighted

Indexing JSON - problem

Path Finder

Hi all,

I have json data that incoming from FIREEYE but can't parsing.
I'm working with cluster environment.

inputs.conf on the heavy forwarder:

Blockquote

[tcp://6012]
index=fireeye
sourcetype=
json
disabled=0

Blockquote

The events shown in Splunk but not parsing.

Tags (1)
0 Karma
Highlighted

Re: Indexing JSON - problem

Builder

Hello,

I think you should assing json KV_MODE for your sourcetype, stantz like this in props.conf

[_json] 
KV_MODE = json

May be you need to set TIMEFORMAT and LINEBREAKER as well.

If the above doesn't work thanks to send sample from log.

Regards

0 Karma
Highlighted

Re: Indexing JSON - problem

Path Finder

Hi,

As I mentioned - I'm working with cluster environment.
accordingly, Where I need to edit the props.conf? in the cluster master?

0 Karma