Getting Data In

Json field not extracted in Splunk DB Connect Input via SQL Server : using Splunk DB Connect 2.0

zanjani786
Engager

i have made an INPUT Field through MS SQL SERVER, There is a column in my table which has JSON values, SPLUNK DB Connect is not showing this json value in any of it's event or fields. it is showing only '{' in the JSON field.
Please help n guide me to resolve this issue or parse the json key, values in to the new column.
Thanks,

popalzie
New Member

Was there ever a solution found for this issue? I am facing the same problem where the datatype I am returning from the database is of type JSON and being inputed using DBX. In Splunk, however, the field just shows as "{". Example below:

json_returned_from_db="{"id":1234}"

The value here is being treated as a String and so the first 2 double quotes encompasess the { and that is what is returned in the field in Splunk.

I want it to return the result as a JSON type preferably.

Thanks!

0 Karma

grittonc
Contributor

What sourcetype are you using?

0 Karma

zanjani786
Engager

i have connection with MS-SQL Server in my input database. and gave my source type an anonymous name

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...