Splunk Dev

Dev Tutorial question about "DESCRIPTION: AInterpidPanoramaofaMadScientistAndaBoywhomustRedeemBoyinAMonastery"

jcorcoran508
Path Finder

 

I have a question on the Dev tutorial as I am unable to figure the behavior or is the output expected under the

DESCRIPTION: AInterpidPanoramaofaMadScientistAndaBoywhomustRedeemBoyinAMonastery

All the words in “DESCRIPTION” are not delimited a by a white space , is the normal behavior ?

 

Module 1 of the Splunk>Dev tutorial 

https://dev.splunk.com/enterprise/tutorials/module_getstarted/

Set up the sample data bundle

To get the Eventgen sample bundle and send it to the devtutorial index, do the following steps:

  1. Go to https://github.com/splunk/eventgen/blob/develop/tests/sample_bundle.zip and click Download to download the Eventgen sample data file, sample_bundle.zip, to your computer.

 

 

 

DESCRIPTION

AInterpidPanoramaofaMadScientistAndaBoywhomustRedeemBoyinAMonastery

 

jcorcoran508_0-1645453520528.jpeg

 

Tags (1)
0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @jcorcoran508,

You can proceed ahead with further modules. The data seems to be perfect and not sure what is the need for delimiting a white space character in the description field. Also, I can see in the screenshot that the description field is properly extracted by the json sourcetype.

---
If you find the answer helpful, an upvote/karma is appreciated
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...