As you have JSON here, you should remember that there are couple of parameters which define how it is handled and extracted. When you are hopping that we help you you must tell all details to us in 1st phase, otherwise we can do just a guess what your question is! So as already asked, tell as much as you can about your situation e.g. with masked/scrambled data, and the we quite possibly could help you! in this case we must know e.g. how long your event is to understand can splunk automatically manage it as json or should we expect that it has managed as encapsulated string and even cut one!
... View more