Hi, I'm having a problem importing JSON formatted data into Splunk. It's retrieved via the Twitter API, stored in a file, and imported into Splunk via the universal forwarder. The result is that I get a single record (not the 94 I'm expecting to see), so I'm thinking it must be something to do with the file data format.
I've uploaded the file into a number of different JSON validators and all but one let it pass. It fails on jsonlint.com BUT, it then is validated fine on pro.jsonlint.com - figure that out!
So has anyone else come across this. I've had a good look in splunkbase, but only found one question similar-ish to this one.
I'm happy to provide further info if it helps, and also provide the file in question (I need more karma points to be able provide links here...).
Thanks.
... View more