Splunk Enterprise

Why are we receiving error from _internal index for Json logs?

Santosh2
Path Finder

We are receiving error from _internal index  for Json logs:

1. error: ERROR JsonLineBreaker - JSON StreamId:1254678906 had parsing error:Unexpected character: "s"

2. error: ERROR JsonLineBreaker - JSON StreamId:1254678906 had parsing error:Unexpected character: "a" 

sample logs:

{  [-]

       level: debug

      message: Creating a new instance of inquiry call

      timestamp: 2022-08-25T20:30:45.678Z

}

 

my props.conf:
TIME_PREFIX=timestamp" : "

TIME_FORMAT= %Y-%m-%dT%H:%M:%S.%3N

MAX_TIMESTAMP_LOOKAHEAD=40

TZ=UTC

how to resolve this issue.

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

I'm not sure about the exact cause of those messages, but it could be because the sample log is not valid JSON.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I'm not sure about the exact cause of those messages, but it could be because the sample log is not valid JSON.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Santosh2
Path Finder

but how can i identify that

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Among other things, proper JSON uses quotation marks around strings.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Santosh2
Path Finder
 
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...