Splunk Dev

Dev Tutorial question about "DESCRIPTION: AInterpidPanoramaofaMadScientistAndaBoywhomustRedeemBoyinAMonastery"

jcorcoran508
Path Finder

 

I have a question on the Dev tutorial as I am unable to figure the behavior or is the output expected under the

DESCRIPTION: AInterpidPanoramaofaMadScientistAndaBoywhomustRedeemBoyinAMonastery

All the words in “DESCRIPTION” are not delimited a by a white space , is the normal behavior ?

 

Module 1 of the Splunk>Dev tutorial 

https://dev.splunk.com/enterprise/tutorials/module_getstarted/

Set up the sample data bundle

To get the Eventgen sample bundle and send it to the devtutorial index, do the following steps:

  1. Go to https://github.com/splunk/eventgen/blob/develop/tests/sample_bundle.zip and click Download to download the Eventgen sample data file, sample_bundle.zip, to your computer.

 

 

 

DESCRIPTION

AInterpidPanoramaofaMadScientistAndaBoywhomustRedeemBoyinAMonastery

 

jcorcoran508_0-1645453520528.jpeg

 

Tags (1)
0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @jcorcoran508,

You can proceed ahead with further modules. The data seems to be perfect and not sure what is the need for delimiting a white space character in the description field. Also, I can see in the screenshot that the description field is properly extracted by the json sourcetype.

---
If you find the answer helpful, an upvote/karma is appreciated
0 Karma
Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...