What does your props.conf file look like? I was having this issue with some of my SendGrid logs. Example of some of the logs:
[{"response":"550 5.1.1 User Unknown ","sg_event_id":"1234567890","sg_message_id":"7410258963","event":"deferred","email":"user1@abc.local","attempt":"23","timestamp":1432305797,"smtp-id":"<random@server.local>"}]
[{"email":"user2@abc.local","timestamp":1432305792,"smtp-id":"<random@server.local>","sg_event_id":"2345678901","sg_message_id":"4108529637","event":"processed"}]
[{"email":"user3@abc.local","timestamp":1432305793,"smtp-id":"<random@server.local>","sg_event_id":"3456789012","sg_message_id":"1085296374","event":"processed"},
{"email":"user4@abc.local","timestamp":1432305793,"smtp-id":"<random@server.local>","sg_event_id":"4567890123","sg_message_id":"0852963741","event":"processed"},
{"email":"user5@abc.local","timestamp":1432305793,"smtp-id":"<random@server.local>","sg_event_id":"5678901234","sg_message_id":"852963710","event":"processed"},
{"email":"user6@abc.local","timestamp":1432305793,"smtp-id":"<random@server.local>","sg_event_id":"6789012345","sg_message_id":"5296374108","event":"processed"},
{"email":"user7@abc.local","timestamp":1432305795,"smtp-id":"<random@server.local>","response":"250 Message Queued (No RCPTS) ","sg_event_id":"7890123456","sg_message_id":"2963741085","event":"delivered"},
{"email":"user8@abc.local","smtp-id":"<random@server.local>","timestamp":1432305796,"response":"250 Backend Replied [7531598520.abcd.server.local]: 2.0.0 Ok: queued as A1B2C3D4 (Mode: n ","sg_event_id":"8901234567","sg_message_id":"9637410852","event":"delivered"},
{"email":"user9@abc.local","timestamp":1432305796,"smtp-id":"<random@server.local>","response":"250 Message Queued (No RCPTS) ","sg_event_id":"9012345678","sg_message_id":"637410852963","event":"delivered"},
{"email":"user0@abc.local","timestamp":1432305796,"smtp-id":"<random@server.local>","response":"250 Message Queued (No RCPTS) ","sg_event_id":"0123456789","sg_message_id":"3741085296","event":"delivered"}]
My props.conf for this sourcetype:
[sendgrid_json]
INDEXED_EXTRACTIONS = json
KV_MODE = none
NO_BINARY_CHECK = true
TIMESTAMP_FIELDS = timestamp
category = Structured
disabled = false
pulldown_type = true
Now it shows up in the nice JSON format.
... View more