Getting Data In

Any way to process mixed Apache and JSON format data

Path Finder

We have some apps that mix apache log and json data in the same log file. Is there a way to extract both data types, and still successfully format the json? We have "INDEXED_EXTRACTIONS = json, KV_MODE = none" in the props.conf file (splunkforwarder-6.4.2), and the apache log lines are ignored. I was under the impression KV_MODE=none would not ignore them. I thought the way we have this set up was supposed to do what I want: Properly format json lines and just ingest other lines without indexing?

Tags (2)
0 Karma


Can you please provide some sample logs (Please mask sensitive data) ?

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!