Splunk Enterprise

raw or json

san4net
New Member

Hi Team, 

We are using splunk enterprises. 

We can ingest data in below  two formats.

1. json 

2. text like "2021-02-08 16:40:39.385 INFO [main ] com.XX.program.Sample:publishToKafka - paymentId:12344 received"

Wanted to know performance wise which one is preferred.   So while doing a query against the data which one will take less time.

 

Thanks

santos

 

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

IMO, raw text is much easier to work with.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...