Getting Splunk to capture JSON fragments

While it is recommended to use machine readable logging structures, it can be difficult to set up Splunk to read them.  Here’ how:

In the props.conf on the universal forwarders, use something like

[mysourcetype]
INDEXED_EXTRACTIONS = JSON
TIMESTAMP_FIELDS = Time
TZ = UTC
KV_MODE = none
AUTO_KV_JSON = false

Basically, I use a subset of this.

Advertisements
This entry was posted in Uncategorized. Bookmark the permalink.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s