I have a lot of experience with front end querying and search time Splunk queries, but I am less familiar with the back-end magic that can happen in Splunk.
I've created an input with DBX that returns an ID and a JSON from our database into Splunk. I tried parsing the JSON with spath, rex sed, and other options for a few hours yesterday, to no avail. If I could set the kv_mode to json in the config file, I think my life will be much easier. My question is, can (and how) would I do this? Are there any documents/previous threads that would have this information? Since the input is a query, and not a static file, I wasn't sure if it was configurable. Any and all info would be greatly appreciated.
I don't think this is possible, sorry. Probably better off with spath.
I don't think this is possible, sorry. Probably better off with spath.