Splunk Enterprise

Fileds not extracting for JSON file from forwarder, but are from GUI upload. I am using the same sourcetype

robertlynch2020
Influencer

Hi

I am using the same source type on the same file.

One is coming in via forwarder and the other is uploaded via GUI. However, the forwarder is not extracting the fields. This means I have to use "patch" to access the fields, this is a pain.

Below is a file from a forwarder, we can see fields are not extracted.

robertlynch2020_0-1697028372227.png

Below is the same file but upload - in this case, the fields are extracted.

robertlynch2020_1-1697028457566.png

This is the sourcetype

[import_json_2]
DATETIME_CONFIG =
INDEXED_EXTRACTIONS = json
KV_MODE = none
LINE_BREAKER = ([\r\n]+)
NO_BINARY_CHECK = true
TIMESTAMP_FIELDS = start_time
TZ = Asia/Beirut
category = Structured
description = JavaScript Object Notation format. For more information, visit http://json.org/
disabled = false
pulldown_type = 1

 

Any ideas - thanks in advance.

Rob

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...