Hello, I am parsing a file in JSON format to splunk entrprise but the sourcetype is not selected automatically, when I chose JSON sourcetype manually the events doesn't parsed correctly, In addition to I put the file in a JSON validator and the result was that the JSON format is valid so what is the problem then ?
Hi,
Can you please let us know how are you ingesting file into Splunk? If Universal Forwarder is sending JSON logfile to Splunk Indexer then try to put below configuration on Universal Forwarder and restart splunk on UF.
props.conf
[yoursourcetype]
INDEXED_EXTRACTIONS = JSON