Getting Data In

Delayed JSON data parsing

rawno
Engager

I am trying to parse JSON data on Splunk. I set up the props file on the server and it is doing the parsing but there is a delay while doing that. When I search; at first result comes as raw data and in 10 sec it automatically refreshes and shows the data in the correct format.
How can I check what's causing this delay?

Checked the metrics and splunkd but couldn't find anything related to this.
Any thoughts??

0 Karma
Get Updates on the Splunk Community!

Splunk Platform | Upgrading your Splunk Deployment to Python 3.9

Splunk initially announced the removal of Python 2 during the release of Splunk Enterprise 8.0.0, aiming to ...

From Product Design to User Insights: Boosting App Developer Identity on Splunkbase

co-authored by Yiyun Zhu & Dan Hosaka Engaging with the Community at .conf24 At .conf24, we revitalized the ...

Detect and Resolve Issues in a Kubernetes Environment

We’ve gone through common problems one can encounter in a Kubernetes environment, their impacts, and the ...