Getting Data In

JSON syntax highlighting not working for strings with greater than 1000 characters?

minerjaime
Engager

Hi, folks -- I'm using Splunk 6.0.1.

I'm trying to ingest JSON and have the JSON syntax highlighting automatically parse my input.

After experimenting, it seems that I can only get the syntax highlighting to work for JSON lines with less than 1000 characters (998 works).

How can I fix this?

I've tried setting TRUNCATE=0 in the app's props.conf file. I've tried resetting the maxvaluesize=10000 within the limits.conf file. Both, yield no luck.

Thanks!

0 Karma

mkemmerer
Explorer

For events I have that are 3000+ lines, I found that when you expand the event to show all lines, the JSON syntax highlighting option appears - at least on 6.2.3 through 6.3.1.

0 Karma

minerjaime
Engager

Thanks, mkemmerer.

My JSON lines are in the realm of 1500 characters in length. When viewing the search results, I can see the entire raw data values, with no option for the syntax highlighting.

I've confirmed, with jsonlint.com, that the JSON is valid.

0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...