Splunk Dev

Dev Tutorial question about "DESCRIPTION: AInterpidPanoramaofaMadScientistAndaBoywhomustRedeemBoyinAMonastery"

jcorcoran508
Path Finder

 

I have a question on the Dev tutorial as I am unable to figure the behavior or is the output expected under the

DESCRIPTION: AInterpidPanoramaofaMadScientistAndaBoywhomustRedeemBoyinAMonastery

All the words in “DESCRIPTION” are not delimited a by a white space , is the normal behavior ?

 

Module 1 of the Splunk>Dev tutorial 

https://dev.splunk.com/enterprise/tutorials/module_getstarted/

Set up the sample data bundle

To get the Eventgen sample bundle and send it to the devtutorial index, do the following steps:

  1. Go to https://github.com/splunk/eventgen/blob/develop/tests/sample_bundle.zip and click Download to download the Eventgen sample data file, sample_bundle.zip, to your computer.

 

 

 

DESCRIPTION

AInterpidPanoramaofaMadScientistAndaBoywhomustRedeemBoyinAMonastery

 

jcorcoran508_0-1645453520528.jpeg

 

Tags (1)
0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @jcorcoran508,

You can proceed ahead with further modules. The data seems to be perfect and not sure what is the need for delimiting a white space character in the description field. Also, I can see in the screenshot that the description field is properly extracted by the json sourcetype.

---
If you find the answer helpful, an upvote/karma is appreciated
0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...