Splunk Search

Issues while parsing lengthy Json

dasnitu5
New Member

We are facing issue while parsing the lengthy Json file. Splunk is picking up incomplete data. Attaching the specifications of source type used, any help would be appreciated. Thanks!!

dasnitu5_0-1611122604897.jpeg

 

 

Labels (1)
0 Karma

to4kawa
Ultra Champion

What happened with that setting? Without specifics, it's hard to tell.

0 Karma

dasnitu5
New Member

 

Hi @to4kawa ,

The given source type(provided in the screenshot) was parsing the long JSON input correctly till few days back. But after migrating from Splunk version 7.3.4 to 8.0.5, the full JSON data is not getting picked up by Splunk.

Is there some attribute present in configuration files of Splunk which defines the length of an event ? If yes, we can try increasing its value so that we get complete data and it gets correctly parsed by the given sourcetype?

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...