Getting Data In

Delayed JSON data parsing

rawno
Engager

I am trying to parse JSON data on Splunk. I set up the props file on the server and it is doing the parsing but there is a delay while doing that. When I search; at first result comes as raw data and in 10 sec it automatically refreshes and shows the data in the correct format.
How can I check what's causing this delay?

Checked the metrics and splunkd but couldn't find anything related to this.
Any thoughts??

0 Karma
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...