Getting Data In

How important is specified JSON format?

ArnasK
Observer

Hello, documentation shows JSON format as a: metadata fields, events field with additional data in it.

Format events for HTTP Event Collector - Splunk Documentation

 

My question is how important is to preserve this structure?  Can you remove "event" nesting?

That's how events looks in Splunk right now, I have to press on a "+" sign to see the actual message.

ArnasK_1-1662704176670.png

 

If I remove the "event" nesting I can see the main message without extra actions.

ArnasK_2-1662704319585.png

 

P.S. if this is of any importance, data is being transferred to Splunk via TCP, not HTTP.

 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...