Hi
I am using the same source type on the same file.
One is coming in via forwarder and the other is uploaded via GUI. However, the forwarder is not extracting the fields. This means I have to use "patch" to access the fields, this is a pain.
Below is a file from a forwarder, we can see fields are not extracted.
Below is the same file but upload - in this case, the fields are extracted.
This is the sourcetype
[import_json_2]
DATETIME_CONFIG =
INDEXED_EXTRACTIONS = json
KV_MODE = none
LINE_BREAKER = ([\r\n]+)
NO_BINARY_CHECK = true
TIMESTAMP_FIELDS = start_time
TZ = Asia/Beirut
category = Structured
description = JavaScript Object Notation format. For more information, visit http://json.org/
disabled = false
pulldown_type = 1
Any ideas - thanks in advance.
Rob