Hi,
I have exactly same issue as below
https://answers.splunk.com/answers/513703/json-breaking-single-string-into-multiple-events.html
so i added below to my props.conf file :
[_json_source]
CHARSET=UTF-8
DATETIME_CONFIG = CURRENT
KV_MODE = json
TRUNCATE = 0
SEDCMD-fixfooters=s/]}//g
LINE_BREAKER = ([\r\n,]*(?:{[^[{]+[)?){"teamInCharge
SHOULD_LINEMERGE = false
NO_BINARY_CHECK = true
disabled = false
pulldown_type = true
The events are breaking correctly but the first line is not coming properly, only as raw text and not in json format.
Could you please help.
The different between the raw text between the 1st event and 2nd event i saw is at the end of the line.
1st line ends with below showing other fields along with raw text:
{"teamInCharge":[], bla bla,"serialNumber":""}]
2nd lines ends with below showing syntax highlighted part also
{"teamInCharge":[], bla bla,"serialNumber":""}
Please help.
... View more