Hello, good mornig.
Currently, I am sending the following data, but when ingested into Splunk, it is not recognized in JSON format.
Feb 5 18:50:30 10.0.30.81 {"LogTimestamp": "Tue Feb 6 00:50:31 2024","Customer": "xxxxxx","SessionID": "xxxxxx","SessionType": "TTN_ASSISTANT_BROKER_STATS","SessionStatus": "TT_STATUS_AUTHENTICATED","Version": "","Platform": "","XXX": "XX-X-9888","Connector": "XXXXXXXX","ConnectorGroup": "XXX XXX XXXXXX GROUP","PrivateIP": "","PublicIP": "18.24.9.8","Latitude": 0.000000,"Longitude": 0.000000,"CountryCode": "","TimestampAuthentication": "2024-01-28T09:26:31.592Z","TimestampUnAuthentication": "","CPUUtilization": 0,"MemUtilization": 0,"ServiceCount": 0,"InterfaceDefRoute": "","DefRouteGW": "","PrimaryDNSResolver": "","HostStartTime": "0","ConnectorStartTime": "0","NumOfInterfaces": 0,"BytesRxInterface": 0,"PacketsRxInterface": 0,"ErrorsRxInterface": 0,"DiscardsRxInterface": 0,"BytesTxInterface": 0,"PacketsTxInterface": 0,"ErrorsTxInterface": 0,"DiscardsTxInterface": 0,"TotalBytesRx": 19162399,"TotalBytesTx": 16432931,"MicroTenantID": "0"}
Can you help me?
Can this line be removed using the forwarder from the props files?
Regards,
Hi @CarolinaHB,
JSON format should be only valid JSON string.
If you can send log by removing first "Feb 5 18:50:30 10.0.30.81" then it should be shown as a JSON.
It's not recognized as JSON format because it isn't JSON format. The text before the first { disqualifies it.
How are you ingesting this event? What are the inputs.conf and props.conf settings?
Hi @CarolinaHB,
JSON format should be only valid JSON string.
If you can send log by removing first "Feb 5 18:50:30 10.0.30.81" then it should be shown as a JSON.
Can this line be removed using the forwarder from the props.conf files?"