I've being working in this issue for two days and still don't undestand what the SEDCMD-class = s/^{//g is NOT removing the starting" { " during the data preview. if i dont remove the starting " { " from the .json file i'm trying to index, splunk will put all the events in 1 line
i have tried many combinations but still not working..data preview always show all event in one line,
SEDCMD-class =s/^{//g
SEDCMD-class =s/^{//
SEDCMD-class =s/{//g
SEDCMD-class =s/{/
when removing manually the starting " { ", splunk is able to display 1 event per record in the .json file...all my .json files start with " { " and this is how Microsoft format it...don't know why
can someone help me to figure this out ???
{
"records":
[
{
"time": "2018-05-11T13:29:03Z",
"GatewayId": "4r566-5678-4753-968f-34568",
"Region": "unknown",
"operationName": "ApplicationGatewayAccess",
"category": "ApplicationGatewayAccessLog",
}
,
{
"time": "2018-05-11T13:29:05Z",
"GatewayId": "4r566-ae57-dfg543-968f-xxx45t67",
"Region": "unknown",
"operationName": "ApplicationGatewayAccess",
"category": "ApplicationGatewayAccessLog",
}
}
... View more