- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Possible to set fields in transforms.conf for a field in a JSON formatted event?
jwalzerpitt
Influencer
05-08-2019
08:03 AM
We are using the Splunk Shibboleth add on app but unfortunately our Shib audit events are formatted as JSON and it's nullifying the audit fields in the transforms.conf file:
[shibboleth:audit-fields]
DELIMS = "|"
FIELDS = auditEventTime,requestBinding,requestId,relyingPartyId,messageProfileId,assertingPartyId,responseBinding,responseId,principalName,authNMethod,releasedAttributeId1,releasedAttributeId2,nameIdentifier,assertion1ID,assertion2ID
All of the K/V pairs that should be parsed are in the 'Event' field in the JSON formatted event with the | delimiter.
Is there a way to modify the transforms.conf file so that it looks in the Event field for the values to parse?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
woodcock
Esteemed Legend
05-11-2019
09:27 PM
To turn off automatic JSON interpretation, do this on your search head:
[shibboleth:audit-fields]
KV_MODE = none
AUTO_KV_JSON = false