Hello,
I have an issue with the json data that is being ingested into Splunk using Universal Forwarder. Some times the json entries are ingested as individual entries in Splunk and other times the entire content is loaded as one single event. I tried to search for some special characters that might be causing this issue, but I wasn't able to find any. Attached is a print screen with 2 examples, one that is being loaded as expected and the another where json is not correctly parsed.
Did someone already faced something similar? What should I do to fix it?
... View more