Getting Data In

auto parse json data failed by source type configuration in splunk8

bigq
New Member

case:

transfer data as json format from splunk 6.x to splunk 8 or splunk8.1,failed,

did not parse the json format success by the following set up:

but i can do work well from splunk6.x to splunk 7, so is this a splunk 8 bug? or does there has some workaround solution?

bigq_0-1603722375078.png

 

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...