Well, depending on the formatting of the json log files, you at least need the following in props.conf: SHOULD_LINEMERGE = false If the data is not prettyprinted, the following should help: LINE_BREAKER= \}(,)\{ If the data is prettyprinted, the following may be used to allow for whitespaces between the comma and the curly brace: LINE_BREAKER = \}(,\s*)\{
... View more
What software/hardware are you using as a reverse proxy? And how is that set up?
Any info on what is inside the following two files could also be helpful.
$SPLUNK_HOME/var/log/splunk/web_access.log
$SPLUNK_HOME/var/log/splunk/web_service.log
Also the logfiles for the reverse proxy could be helpful.
... View more