Getting Data In

Multiple Json types in one file. How do i get data into Splunk

robertlynch2020
Motivator

Hi

I have one file with multiple JSON types in it.
What is the best way to get this data into Splunk.
I dont think i can use a universal forwarder as i cant specify the sourcetype as i is multiple.

Someone said use a heavy forward and do the work of splitting the data into different source types before i send it.

Is this the correct approach?

Thanks
Robert Lynch

1 Solution

robertlynch2020
Motivator
0 Karma

robertlynch2020
Motivator
0 Karma

starcher
Influencer

If the source can be edited to write to different files per sourcetype that is most ideal.

Another option that doesn't involve the universal forwarder is ingest the file using python and send to Splunk HTTP Event collector. A bit more complex but more flexible than doing regex routing at indexers.

0 Karma

niketn
Legend

@robertlynch2020, your indexer can also do this job, but better approach like you have said is to use heavy forward to set different sourcetype based on different JSON from the same source through props.conf and transforms.conf for sourcetype override.

Refer to Splunk Documentation : http://docs.splunk.com/Documentation/Splunk/latest/Data/Advancedsourcetypeoverrides#Example:_Assign_...

And Splunk Blog: https://www.splunk.com/blog/2010/02/11/sourcetypes-gone-wild.html

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

robertlynch2020
Motivator

Hi

Thanks, this is the answer i went with 🙂

0 Karma

splunker12er
Motivator

spath command, it will do that for you, you may refer to the below link for using spath

http://docs.splunk.com/Documentation/Splunk/6.3.3/SearchReference/spath

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...