Getting Data In

API json preview field

grittonc
Contributor

As seen in https://docs.splunk.com/Documentation/Splunk/7.2.3/RESTUM/RESTusing#Example_B:_JSON_response_format_...,
there is a field added to the json output that is called "preview". I've never seen it be anything other than "false". Does anyone know what this field is, and whether I can remove it from the output?

Tags (2)
0 Karma

nickv2002
Engager

It's not even valid JSON you're exporting but, the rational for how and why these preview fields are there is explained in this answer

0 Karma

nickv2002
Engager
0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...