Hi,
we are ingesting Couchbase JSON Documents into Splunk Cloud using Kafka.
When I open the same document (1st one ingested in Splunk - _raw and 2nd one is Couchbase JSON) and compare in Visual Studio Code, I can see differences as shown below:
Splunk syntax highlighted data for this record is identical to original Couchbase JSON.
Can you please help me understand why _raw is showing this data differently and also is there any way to get _raw data in the same format at original JSON?
Thank you.
@madhav_dholakia - Splunk _raw shows the price as "17.0", I'm sure that Splunk cannot convert 17 to 17.0
Hence, I'm leaning towards that something else is wrong and Splunk is not modifying anything in the data unless you explicitly added any parsing configs in Splunk.
I hope this helps!!!
thanks @VatsalJagani - Couchbase JSON Document is also showing 17 and not 17.0
so here, Source System (Couchbase) and Splunk Record (when viewed as "highlight syntax") are same, its just Splunk Record _raw is different.
What could be possibly causing this?
Thank you.
@madhav_dholakia - What I'm aware of is Splunk _raw what's coming from the system unless you are explicitly writing config to make changes by props.conf, but otherwise Splunk has no functionality to make changes.
To me it looks like, the actual value is 17.0, but preview is simplifing to 17 on both system.
I hope this helps!!!
apologies for the delayed response - I am getting this checked from Couchbase side if raw data there showing the same values. Thank you.