Getting Data In

How to edit my props.conf configuration to extract individual events from a JSON array?

dhavamanis
Builder

Can you please tell us how to extract an individual events from json array during the indexing,

Sample input:

{
  "Value": [
    {
      "date": "2016-06-10",
      "applicationId": "app1",
      "applicationName": "T NOW",
      "deviceType": "PC",
      "orderName": "",
      "storeClient": "Windows Store (client)",
      "osVersion": "Windows 10",
      "market": "US",
      "gender": "Unknown",
      "ageGroup": "35-49",
      "acquisitionType": "Free",
      "acquisitionQuantity": 1
    },
    {
      "date": "2016-06-09",
      "applicationId": "app1",
      "applicationName": "T NOW",
      "deviceType": "PC",
      "orderName": "",
      "storeClient": "Store (client)",
      "osVersion": "Windows 8.1",
      "market": "US",
      "gender": "Unknown",
      "ageGroup": "Unknown",
      "acquisitionType": "Free",
      "acquisitionQuantity": 5
    }]
}

We have tried source settings like below in props.conf and seems it is not splitting the events correctly. Can you please provide the correct properties to break events for each values in the json array and assign the date field value as the event's timestamp?

[mobile_win_json]
INDEXED_EXTRACTIONS = json
KV_MODE = json
NO_BINARY_CHECK = true
BREAK_ONLY_BEFORE = ^{
SHOULD_LINEMERGE = false
TIMESTAMP_FIELDS = date
TIME_FORMAT = %Y-%m-%d
TRUNCATE = 0
category = Custom
description = json filed extraction from array of value
disabled = false
pulldown_type = true

ryanoconnor
Builder
  1. The following line can be removed since "SHOULD_LINEMERGE" is set to false.

    BREAK_ONLY_BEFORE = ^{

    1. Can you post a sample JSON event that you're seeing in Splunk? This appears to be valid JSON so it should be extracting.
0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...