Getting Data In

When I search for _json sourcetype, I am not getting the results as highlighted

mintughosh
Path Finder

When I search for _json sourcetype, I am not getting the results as highlighted like json sourcetype should have been, I tried the following options on props.conf in Heavy forwarder where the Rest API modular input is installed

[_json]
kv_store = JSON
Index_extractions = json

I have tried all the above options but still not working

Tags (2)
0 Karma

MuS
Legend

Hi mintughosh,

is this a typo kv_store = JSON?

You should either use KV_MODE = json which is a search time setting on the search head
OR
INDEXED_EXTRACTIONS = JSON on your input instance, see the docs for more details http://docs.splunk.com/Documentation/Splunk/latest/Admin/Configurationparametersandthedatapipeline#S...

Hope this helps ...

cheers, MuS

0 Karma

mintughosh
Path Finder

yes, that was a typo. Ok. I wil try to make the changes on the Search head clusters and see if it works

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...