Hello, documentation shows JSON format as a: metadata fields, events field with additional data in it.
Format events for HTTP Event Collector - Splunk Documentation
My question is how important is to preserve this structure? Can you remove "event" nesting?
That's how events looks in Splunk right now, I have to press on a "+" sign to see the actual message.
If I remove the "event" nesting I can see the main message without extra actions.
P.S. if this is of any importance, data is being transferred to Splunk via TCP, not HTTP.