Getting Data In

Any way to process mixed Apache and JSON format data

wsanderstii
Path Finder

We have some apps that mix apache log and json data in the same log file. Is there a way to extract both data types, and still successfully format the json? We have "INDEXED_EXTRACTIONS = json, KV_MODE = none" in the props.conf file (splunkforwarder-6.4.2), and the apache log lines are ignored. I was under the impression KV_MODE=none would not ignore them. I thought the way we have this set up was supposed to do what I want: Properly format json lines and just ingest other lines without indexing?

Tags (2)
0 Karma

harsmarvania57
Ultra Champion

Can you please provide some sample logs (Please mask sensitive data) ?

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...