<?xml version="1.0" ?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
	<channel>
		<title>Splunk Base : SplunkGeneral : #3864</title>
		<link>http://www.splunk.com/support/forum:SplunkGeneral/3864</link>
		<description></description>
		<pubDate>Mon, 13 Feb 2012 12:08:21 PST</pubDate>
		<lastBuildDate>Mon, 13 Feb 2012 12:08:21 PST</lastBuildDate>
		<language>en-us</language>
		<copyright>http://creativecommons.org/licenses/by-nc-nd/2.5/</copyright>
		<item>
			<title>JSON Formatted Logs</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3864/13555</link>
			<description>&lt;p&gt;Thanks araitz it worked great for me.&lt;/p&gt;

&lt;p&gt;You may need to add &amp;quot;REPEAT_MATCH=true&amp;quot; to the transform to get all the key value pairs out of the log&lt;/p&gt;

</description>
			<pubDate>Tue, 09 Mar 2010 09:34:11 PST</pubDate>
			<author>davidsg</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3864/13555</guid>
		</item>
		<item>
			<title>JSON Formatted Logs</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3864/12911</link>
			<description>&lt;p&gt;Let's assume that your sourcetype is &amp;quot;json&amp;quot; - this is props.conf:&lt;/p&gt;


&lt;div class=&quot;wikiCode&quot;&gt;&lt;pre&gt;

[json]
SHOULD_LINEMERGE=true
BREAK_ONLY_BEFORE=^\d+\s+\d{2}\:\d{2}\:\d{2}
TIME_PREFIX=^
TIME_FORMAT=%b %d %T
MAX_TIMESTAMP_LOOKAHEAD=15
REPORT-json=json_kv
&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;This is transforms.conf:&lt;/p&gt;


&lt;div class=&quot;wikiCode&quot;&gt;&lt;pre&gt;

[json_kv]
REGEX = \&amp;quot;([^\&amp;quot;]+)\&amp;quot;\:\&amp;quot;([^\&amp;quot;]+)\&amp;quot;
FORMAT= $1::$2
MV_ADD=true
&lt;/pre&gt;&lt;/div&gt;

</description>
			<pubDate>Tue, 02 Feb 2010 15:48:36 PST</pubDate>
			<author>araitz</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3864/12911</guid>
		</item>
		<item>
			<title>JSON Formatted Logs</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3864/12910</link>
			<description>&lt;p&gt;I am in a similar position, looking to get JSON formatted data into splunk. The following are 10 redacted events.&lt;/p&gt;

&lt;p&gt;&lt;tt&gt;Jan 20 04:01:14 ccw1 cc_log: {&amp;quot;uri&amp;quot;:&amp;quot;\/example-path\/node\/12109&amp;quot;,&amp;quot;act&amp;quot;:&amp;quot;view&amp;quot;,&amp;quot;ccl&amp;quot;:&amp;quot;4b56f08ac4705&amp;quot;,&amp;quot;sid&amp;quot;:null,&amp;quot;ip&amp;quot;:&amp;quot;127.0.0.1&amp;quot;}&lt;br /&gt;
Jan 20 04:01:29 ccw1 cc_log: {&amp;quot;uri&amp;quot;:&amp;quot;\/example-path\/node\/22323&amp;quot;,&amp;quot;act&amp;quot;:&amp;quot;view&amp;quot;,&amp;quot;ccl&amp;quot;:&amp;quot;4b56f09928ae7&amp;quot;,&amp;quot;sid&amp;quot;:null,&amp;quot;ip&amp;quot;:&amp;quot;127.0.0.1&amp;quot;}&lt;br /&gt;
Jan 20 04:01:34 ccw1 cc_log: {&amp;quot;uri&amp;quot;:&amp;quot;\/example-path\/node\/98899&amp;quot;,&amp;quot;act&amp;quot;:&amp;quot;view&amp;quot;,&amp;quot;ccl&amp;quot;:&amp;quot;4b56f09e1ad7b&amp;quot;,&amp;quot;sid&amp;quot;:null,&amp;quot;ip&amp;quot;:&amp;quot;127.0.0.1&amp;quot;}&lt;br /&gt;
Jan 20 04:01:43 ccw1 cc_log: {&amp;quot;uri&amp;quot;:&amp;quot;\/example-path\/node\/872348&amp;quot;,&amp;quot;act&amp;quot;:&amp;quot;view&amp;quot;,&amp;quot;ccl&amp;quot;:&amp;quot;4b56f0a705ca4&amp;quot;,&amp;quot;sid&amp;quot;:null,&amp;quot;ip&amp;quot;:&amp;quot;127.0.0.1&amp;quot;}&lt;br /&gt;
Jan 20 04:01:44 ccw1 cc_log: {&amp;quot;uri&amp;quot;:&amp;quot;\/example-path\/node\/22112133&amp;quot;,&amp;quot;act&amp;quot;:&amp;quot;view&amp;quot;,&amp;quot;ccl&amp;quot;:&amp;quot;4b56f0a87e588&amp;quot;,&amp;quot;sid&amp;quot;:null,&amp;quot;ip&amp;quot;:&amp;quot;127.0.0.1&amp;quot;}&lt;br /&gt;
Jan 20 04:01:49 ccw1 cc_log: {&amp;quot;uri&amp;quot;:&amp;quot;\/example-path\/node\/2232331&amp;quot;,&amp;quot;act&amp;quot;:&amp;quot;view&amp;quot;,&amp;quot;ccl&amp;quot;:&amp;quot;4b56f0ad06de2&amp;quot;,&amp;quot;sid&amp;quot;:null,&amp;quot;ip&amp;quot;:&amp;quot;127.0.0.1&amp;quot;}&lt;br /&gt;
Jan 20 04:01:49 ccw1 cc_log: {&amp;quot;uri&amp;quot;:&amp;quot;\/example-path\/node\/555&amp;quot;,&amp;quot;act&amp;quot;:&amp;quot;view&amp;quot;,&amp;quot;ccl&amp;quot;:&amp;quot;4b56f0ad071cc&amp;quot;,&amp;quot;sid&amp;quot;:null,&amp;quot;ip&amp;quot;:&amp;quot;127.0.0.1&amp;quot;}&lt;br /&gt;
Jan 20 04:01:49 ccw1 cc_log: {&amp;quot;uri&amp;quot;:&amp;quot;\/example-path\/node\/2&amp;quot;,&amp;quot;act&amp;quot;:&amp;quot;view&amp;quot;,&amp;quot;ccl&amp;quot;:&amp;quot;4b56f0ad47f6a&amp;quot;,&amp;quot;sid&amp;quot;:null,&amp;quot;ip&amp;quot;:&amp;quot;127.0.0.1&amp;quot;}&lt;br /&gt;
Jan 20 04:01:57 ccw1 cc_log: {&amp;quot;uri&amp;quot;:&amp;quot;\/example-path\/node\/register&amp;quot;,&amp;quot;act&amp;quot;:&amp;quot;register&amp;quot;,&amp;quot;ccl&amp;quot;:&amp;quot;4b56f0b5d0796&amp;quot;,&amp;quot;sid&amp;quot;:null,&amp;quot;ip&amp;quot;:&amp;quot;127.0.0.1&amp;quot;}&lt;br /&gt;
Jan 20 04:02:06 ccw1 cc_log: {&amp;quot;uri&amp;quot;:&amp;quot;\/example-path\/node\/login&amp;quot;,&amp;quot;act&amp;quot;:&amp;quot;login&amp;quot;,&amp;quot;ccl&amp;quot;:&amp;quot;4b56f0beaeba9&amp;quot;,&amp;quot;sid&amp;quot;:null,&amp;quot;ip&amp;quot;:&amp;quot;127.0.0.1&amp;quot;}&lt;/tt&gt;&lt;/p&gt;

</description>
			<pubDate>Tue, 02 Feb 2010 14:51:33 PST</pubDate>
			<author>rustaml</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3864/12910</guid>
		</item>
		<item>
			<title>JSON Formatted Logs</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3864/12663</link>
			<description>&lt;p&gt;Can you post a sample event or two?&lt;/p&gt;

</description>
			<pubDate>Mon, 18 Jan 2010 07:38:52 PST</pubDate>
			<author>araitz</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3864/12663</guid>
		</item>
		<item>
			<title>JSON Formatted Logs</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3864/12655</link>
			<description>&lt;p&gt;I have an application which outputs in the format&lt;/p&gt;

&lt;p&gt;timestamp|{json}&lt;/p&gt;

&lt;p&gt;I did this because I am going to write another application for searching and reporting and the easiest way to read back in this data was for it to be JSON formatted.&lt;/p&gt;

&lt;p&gt;Then I thought, perhaps I can just use splunk.  However despite the documentation stating that it can handle logs/events in any format, JSON does not seem to be catered for at all (except for regex'ing).&lt;/p&gt;

&lt;p&gt;Now I can write a simple java application to parse the logs into simple name value pairs for input into splunk using the Java API, looks like 30 minutes effort, but am lazy and would prefer not to.&lt;/p&gt;

&lt;p&gt;Have I missed something ?  Any ideas ?&lt;/p&gt;

</description>
			<pubDate>Sat, 16 Jan 2010 19:39:53 PST</pubDate>
			<author>lordbuddha</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3864/12655</guid>
		</item>
	</channel>
</rss>

