Getting Data In

Problem: Importing file of JSON data from Twitter results in one single event?

djtaylor74
New Member

Hi, I'm having a problem importing JSON formatted data into Splunk. It's retrieved via the Twitter API, stored in a file, and imported into Splunk via the universal forwarder. The result is that I get a single record (not the 94 I'm expecting to see), so I'm thinking it must be something to do with the file data format.

I've uploaded the file into a number of different JSON validators and all but one let it pass. It fails on jsonlint.com BUT, it then is validated fine on pro.jsonlint.com - figure that out!

So has anyone else come across this. I've had a good look in splunkbase, but only found one question similar-ish to this one.

I'm happy to provide further info if it helps, and also provide the file in question (I need more karma points to be able provide links here...).

Thanks.

Tags (3)
0 Karma

davecroto
Splunk Employee
Splunk Employee

You can solve this parsing problem by installing and using this app:

http://splunk-base.splunk.com/apps/56296/twitter-for-splunk

0 Karma

djtaylor74
New Member

I took a look at this app, but when entering my credentials on the set-up page I get:

Encountered the following error while trying to update: In handler 'localapps': Could not validate password for id="credential::djtaylor74:"

Anyone else encountered this type of error? Could it be a firewall issue?

So I've not been able to get any further with that particular app, and also I don't know if it'll meet my needs as I'm making very specific calls to the Twitter API and manipulating the JSON response before storing it.

Any further help greatly appreciated.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...