Hi @LordSnooz
For this purpose, I going to use the Splunk _json sourcetype default settings (It works in my case)
My sourcetype name for this example will be "test"
A workaround to do this would be the following:
1) Create a custom sourcetype
2) Configure your custom sourcetype (in opt/splunk/etc/system/local/props.conf) as:
[ test ]
SHOULD_LINEMERGE=true
LINE_BREAKER=([\r\n]+)
NO_BINARY_CHECK=true
CHARSET=AUTO
INDEXED_EXTRACTIONS=json
KV_MODE=none
category=Structured
description=JavaScript Object Notation format. For more information, visit http://json.org/
disabled=false
pulldown_type=true
EVAL-my_tag = tag
3) Configure your data input (Using the sourcetype created, [ test ] in my case )
4) Search your results
index=< your_index_name > sourcetype=test my_tag="7b91119dbad4"
Please try and let me know if it is working for you or not.
... View more