Splunk Search

Issues while parsing lengthy Json

dasnitu5
New Member

We are facing issue while parsing the lengthy Json file. Splunk is picking up incomplete data. Attaching the specifications of source type used, any help would be appreciated. Thanks!!

dasnitu5_0-1611122604897.jpegdasnitu5_0-1611122604897.jpeg

 

 

Labels (1)
0 Karma

to4kawa
Ultra Champion

What happened with that setting? Without specifics, it's hard to tell.

0 Karma

dasnitu5
New Member

 

Hi @to4kawa ,

The given source type(provided in the screenshot) was parsing the long JSON input correctly till few days back. But after migrating from Splunk version 7.3.4 to 8.0.5, the full JSON data is not getting picked up by Splunk.

Is there some attribute present in configuration files of Splunk which defines the length of an event ? If yes, we can try increasing its value so that we get complete data and it gets correctly parsed by the given sourcetype?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...