Splunk Enterprise

Fileds not extracting for JSON file from forwarder, but are from GUI upload. I am using the same sourcetype

robertlynch2020
Motivator

Hi

I am using the same source type on the same file.

One is coming in via forwarder and the other is uploaded via GUI. However, the forwarder is not extracting the fields. This means I have to use "patch" to access the fields, this is a pain.

Below is a file from a forwarder, we can see fields are not extracted.

robertlynch2020_0-1697028372227.png

Below is the same file but upload - in this case, the fields are extracted.

robertlynch2020_1-1697028457566.png

This is the sourcetype

[import_json_2]
DATETIME_CONFIG =
INDEXED_EXTRACTIONS = json
KV_MODE = none
LINE_BREAKER = ([\r\n]+)
NO_BINARY_CHECK = true
TIMESTAMP_FIELDS = start_time
TZ = Asia/Beirut
category = Structured
description = JavaScript Object Notation format. For more information, visit http://json.org/
disabled = false
pulldown_type = 1

 

Any ideas - thanks in advance.

Rob

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...