Hi,
I am trying to index JSON data but Splunk refused to index it and I have no errors in logs.
The format of my data is :
{"test1":"2017-08-31", "test2":"12.34.56"}
I tried many format :
{"test1":"2017-08-31", "test2":"12.34.56"}" => not indexed
{"test1":"12.34.56", "test2":"2017-08-31"}" => not indexed
{"test1":"2017-08-31", "test2":2017/08/3"}" = > indexed successfully
{"test1":"2017.08.31", "test2":17.08.3"}" => indexed successfully
{"test1":"2017_08_31", "test2":17.08.3"}" => indexed successfully
Why Splunk doesn't want to index my JSON with these data :
{"test1":"2017-08-31","test2":"12.34.56"}
Thanks for your help
... View more