Getting Data In

HTTP Event Collector: Why are double quotes not escaped for a properly formatted JSON string?

unclethan
Path Finder

A properly formatted JSON string will escape the double quotes. However the HEC does not translate that accordingly.

e.g JSON message to HEC: {"event":"somefield=\"a value with spaces\""}
the value for somefield is \"a value with spaces\"
when it should have the value a value with spaces

Any information on how to rectify this would be appreciated.

1 Solution

gblock_splunk
Splunk Employee
Splunk Employee

This is fixed in the next version of Splunk, 6.4 which will be shipping very soon.

View solution in original post

0 Karma

gblock_splunk
Splunk Employee
Splunk Employee

This is fixed in the next version of Splunk, 6.4 which will be shipping very soon.

0 Karma

IdoTwiggle
Engager

Hi,

We're currently using Splunk version 6.4.1 and still experiencing this bug.
Can you verify if / on what version was it fixed to let us know what version should we upgrade to?

Thanks,
Ido

Get Updates on the Splunk Community!

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...

Index This | What’s a riddle wrapped in an enigma?

September 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...