I am trying to parse JSON data on Splunk. I set up the props file on the server and it is doing the parsing but there is a delay while doing that. When I search; at first result comes as raw data and in 10 sec it automatically refreshes and shows the data in the correct format.
How can I check what's causing this delay?
Checked the metrics and splunkd but couldn't find anything related to this.
Any thoughts??