Getting Data In
Highlighted

Conf file precedence issue, JSON extraction

Engager

props definition is below, when i save it in app\search\local directory it doesn't work as expected{events are not broken properly}.
When saving the same configuration in system\local it works fine.

what am I missing?

[samplejson]
TIMEPREFIX = ("observedTime":")
TIME
FORMAT = %Y-%m-%dT%H:%M:%S
MAXTIMESTAMPLOOKAHEAD = 19
LINEBREAKER = ([\n\r]+){
SHOULD
LINEMERGE = false
TRUNCATE = 0

0 Karma
Highlighted

Re: Conf file precedence issue, JSON extraction

Super Champion

ensure that [samplejson] stanza is not used in another app
The best way you can check is to use debug command on btool

$SPLUNK_HOME/bin/splunk cmd btool props list --debug >/tmp/props.btool.out
$SPLUNK_HOME/bin/splunk cmd btool transforms list --debug >/tmp/transforms.btool.out

And check for the [samplejson] if its coming from your app or somewhere else

View solution in original post

0 Karma