Splunk Search

Issues while parsing lengthy Json

dasnitu5
New Member

We are facing issue while parsing the lengthy Json file. Splunk is picking up incomplete data. Attaching the specifications of source type used, any help would be appreciated. Thanks!!

dasnitu5_0-1611122604897.jpeg

 

 

Labels (1)
0 Karma

to4kawa
Ultra Champion

What happened with that setting? Without specifics, it's hard to tell.

0 Karma

dasnitu5
New Member

 

Hi @to4kawa ,

The given source type(provided in the screenshot) was parsing the long JSON input correctly till few days back. But after migrating from Splunk version 7.3.4 to 8.0.5, the full JSON data is not getting picked up by Splunk.

Is there some attribute present in configuration files of Splunk which defines the length of an event ? If yes, we can try increasing its value so that we get complete data and it gets correctly parsed by the given sourcetype?

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...