Getting Data In

Fields Extraction from JSON File

newsplunker1
Path Finder

Im monitoring a JSON file and forwarding the data using UF to my indexers . Im having problems to extract the JSON fields . Here is my props file . Nothing is being extracted ( i was trying to upload a screenshot but i dont have enought points ) . i know its something with the props but im unable to figure it out . any help would be appreciated

[test]
DATETIME_CONFIG =
INDEXED_EXTRACTIONS = json
KV_MODE = none
LINE_BREAKER = ([\r\n]+)
NO_BINARY_CHECK = true
category = Structured
disabled = false
pulldown_type = true

Thanks

Tags (2)
0 Karma

wwhite12
Path Finder

Check this out, https://answers.splunk.com/answers/556279/why-would-indexed-extractionsjson-in-propsconf-be.html

The props.conf has to be on the UF with the INDEXED_EXTRACTIONS and the props also has to be on the SH with the KV_MODE=NONE

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...