Knowledge Management

Onboarding JSON extract

RobertEttinger8
Explorer

Hi,

I am currently onboarding some data from a different instance of Splunk using a REST API call ... The data produced is JSON and it includes, sourcetype, source, host, _time and _raw.

Is there any way I can match the details from the JSON extract to the corresponding fields in my local instance (i.e., source, sourcetype and host)?

How can I also get Splunk to automatically extract the results._raw field? Do I need to create field extraction for all fields?

the event is currently being onboarded like this:

7/18/19
4:15:00.041 AM

{ [-]
offset: 7

preview: false

result: { [-]
_raw: 2019-07-18 02:15:00.041, LONG_RUN_TX="0"

_serial: 3

_si: [ [+]
]

_sourcetype: sql_x

_subsecond: .041

_time: 2019-07-18 02:15:00.041 GMT

host: SQL01
source: sqlx_extract_log

sourcetype: sqlx_extract

}

}

Thank you.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...