Quantcast
Channel: Questions in topic: "props.conf"
Viewing all articles
Browse latest Browse all 1485

Indexing JSON data

$
0
0
Hi, I created a sourcetype (props.conf) to parse my json files. A local input (index once) was created only to test the props.conf and it works fine! When I tried to create a continuously monitor file the events didn't appear in Splunk. I tried to monitor the entire folder (*.json) and a specific json file. Has anyone had something similar? follow my props.conf [json_mention] TRUNCATE = 0 BREAK_ONLY_BEFORE_DATE = false SHOULD_LINEMERGE = false LINE_BREAKER = ({\s+"location":) MUST_BREAK_AFTER = {\s+"location": TIME_FORMAT=%Y-%m-%d %H:%M:%S TIME_PREFIX=({\s+"collected_at":\s+") MAX_TIMESTAMP_LOOKAHEAD=20 Best regards,

Viewing all articles
Browse latest Browse all 1485

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>