Getting Data In

How to exclude/ignore writing an error to splunkd.log

nareshinsvu
Builder

Hi,

Is there a way to tell splunk not to write a particular error message to splunkd.log?

I am getting hit by below error continuously and I can't fix JSON inputs which are coming from external source.

My splunkd.log has only these lines and nothing else.

09-30-2019 14:45:25.717 +1000 ERROR JsonLineBreaker - JSON StreamId:10924785040871047960 had parsing error:Unexpected character: '-' - .......................

My props.conf is like

[my_json]
SEDCMD-strip_prefix = s/^[^{]+//g
INDEXED_EXTRACTIONS=JSON
NO_BINARY_CHECK = true
category = Custom
description = my_json_custom
disabled = false
pulldown_type = true
DATETIME_CONFIG = CURRENT
TRUNCATE = 100000
MAX_EVENTS = 10000
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi nareshinsvu,
if you want, you can filter events before indexing (see https://docs.splunk.com/Documentation/Splunk/7.3.1/Forwarding/Routeandfilterdatad ) but why you want this?
I think that all the information can be useful to debug a problem when needed, if you want to exclude them fron your searches use a NOT clause in yout search so you can exclude them!

Anyway to filter these events, you can use something like this:
In props.conf

[my_json]
TRANSFORMS-null= setnull

In transforms.conf

[setnull]
REGEX = ERROR JsonLineBreaker - JSON StreamId:\d+ had parsing error:Unexpected character
DEST_KEY = queue
FORMAT = nullQueue

If instead you want to exclude these events from your searches, see something like this:

your_search NOT ("ERROR JsonLineBreaker - JSON StreamId:" "had parsing error:Unexpected character")
| ...

Bye.
Giuseppe

0 Karma

nareshinsvu
Builder

Hi Giuseppe,

You got my question wrong. Below is my splunkd.log file on forwarders. Not the source file content being indexed

I am getting these lines in the splunk logs while indexing JSON data (from my source data which is a mix of JSON and non-JSON). I am successfully getting my JSON data indexed. But my splunkd.log is continuously filled with these lines which I want to avoid.

09-30-2019 14:45:25.717 +1000 ERROR JsonLineBreaker - JSON StreamId:10924785040871047960 had parsing error:Unexpected character: '-' - .......................
0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...