Getting Data In

JSON syntax highlighting not working for strings with greater than 1000 characters?

minerjaime
Engager

Hi, folks -- I'm using Splunk 6.0.1.

I'm trying to ingest JSON and have the JSON syntax highlighting automatically parse my input.

After experimenting, it seems that I can only get the syntax highlighting to work for JSON lines with less than 1000 characters (998 works).

How can I fix this?

I've tried setting TRUNCATE=0 in the app's props.conf file. I've tried resetting the maxvaluesize=10000 within the limits.conf file. Both, yield no luck.

Thanks!

0 Karma

mkemmerer
Explorer

For events I have that are 3000+ lines, I found that when you expand the event to show all lines, the JSON syntax highlighting option appears - at least on 6.2.3 through 6.3.1.

0 Karma

minerjaime
Engager

Thanks, mkemmerer.

My JSON lines are in the realm of 1500 characters in length. When viewing the search results, I can see the entire raw data values, with no option for the syntax highlighting.

I've confirmed, with jsonlint.com, that the JSON is valid.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...