Getting Data In

When I search for _json sourcetype, I am not getting the results as highlighted

mintughosh
Path Finder

When I search for _json sourcetype, I am not getting the results as highlighted like json sourcetype should have been, I tried the following options on props.conf in Heavy forwarder where the Rest API modular input is installed

[_json]
kv_store = JSON
Index_extractions = json

I have tried all the above options but still not working

Tags (2)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi mintughosh,

is this a typo kv_store = JSON?

You should either use KV_MODE = json which is a search time setting on the search head
OR
INDEXED_EXTRACTIONS = JSON on your input instance, see the docs for more details http://docs.splunk.com/Documentation/Splunk/latest/Admin/Configurationparametersandthedatapipeline#S...

Hope this helps ...

cheers, MuS

0 Karma

mintughosh
Path Finder

yes, that was a typo. Ok. I wil try to make the changes on the Search head clusters and see if it works

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...