Getting Data In

Can I set kv_mode to JSON in the configuration file for a Splunk DB Connect input?

kknopp
Path Finder

I have a lot of experience with front end querying and search time Splunk queries, but I am less familiar with the back-end magic that can happen in Splunk.

I've created an input with DBX that returns an ID and a JSON from our database into Splunk. I tried parsing the JSON with spath, rex sed, and other options for a few hours yesterday, to no avail. If I could set the kv_mode to json in the config file, I think my life will be much easier. My question is, can (and how) would I do this? Are there any documents/previous threads that would have this information? Since the input is a query, and not a static file, I wasn't sure if it was configurable. Any and all info would be greatly appreciated.

1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

I don't think this is possible, sorry. Probably better off with spath.

View solution in original post

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

I don't think this is possible, sorry. Probably better off with spath.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...