Hi all,
I have json data that incoming from FIREEYE but can't parsing.
I'm working with cluster environment.
inputs.conf on the heavy forwarder:
Blockquote
[tcp://6012]
index=fire_eye
sourcetype=_json
disabled=0
Blockquote
The events shown in Splunk but not parsing.
Hi,
As I mentioned - I'm working with cluster environment.
accordingly, Where I need to edit the props.conf? in the cluster master?
Hello,
I think you should assing json KV_MODE for your sourcetype, stantz like this in props.conf
[_json]
KV_MODE = json
May be you need to set TIME_FORMAT and LINE_BREAKER as well.
If the above doesn't work thanks to send sample from log.
Regards