index=_internal source="*splunkd.log" shows:
ERROR JsonLineBreaker - JSON StreamId:1 had parsing error:Unexpected character while looking for value: 'b' - data_source="http:ABCS", data_host="input-xxxx.cloud.splunk.com:8088", data_sourcetype="_json"
when I change the data to
-d '{"event": "hello world"}'
I get
ERROR JsonLineBreaker - JSON StreamId:0 had parsing error:Unexpected character while looking for value: 'h' - data_source="http:ABC", data_host="input-xxx.cloud.splunk.com:8088", data_sourcetype="_json"
... View more