Hi,
I am being asked if we can ingest two different data formats into one index. Specifically the primary data type is Key Value pairs however from one source the data format is JSON.
A quick search of this site yielded: https://answers.splunk.com/answers/357887/is-there-a-way-to-configure-splunk-to-parse-a-sour.html
So it seems as thought it is possible.
A second related question would be - If that is possible then it this a bad idea... My experience has been that every time I have introduced strange one-offs into any technological solution the super-cool specialized permutation becomes more hassle than it is worth...
... View more