Getting Data In

Can I set kv_mode to JSON in the configuration file for a Splunk DB Connect input?

kknopp
Path Finder

I have a lot of experience with front end querying and search time Splunk queries, but I am less familiar with the back-end magic that can happen in Splunk.

I've created an input with DBX that returns an ID and a JSON from our database into Splunk. I tried parsing the JSON with spath, rex sed, and other options for a few hours yesterday, to no avail. If I could set the kv_mode to json in the config file, I think my life will be much easier. My question is, can (and how) would I do this? Are there any documents/previous threads that would have this information? Since the input is a query, and not a static file, I wasn't sure if it was configurable. Any and all info would be greatly appreciated.

1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

I don't think this is possible, sorry. Probably better off with spath.

View solution in original post

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

I don't think this is possible, sorry. Probably better off with spath.

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...