Getting Data In
Highlighted

How do I properly configure Splunk to index JSON data?

New Member

I'm trying to index a json file (below) using the preview of the Add data>Set sourcetype window, but every configuration I try returns no results.

Would appreciate getting a configuration that works:

{"Version":"1.0","Measures":[{"TopicName":"Topic 1","TopicId":"0001","StartTime":"2015-08-11 02:12:36.23",...}, {"TopicName":"Topic 1","TopicId":"0002","StartTime":"2015-08-11 02:15:36.23",...}...]}

Thanks,
Oded

0 Karma
Highlighted

Re: How do I properly configure Splunk to index JSON data?

SplunkTrust
SplunkTrust

Try this (in the advanced tab)

SHOULD_LINEMERGE = false
TRUNCATE = 500000
DATETIME_CONFIG = CURRENT
KV_MODE = json
0 Karma