Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to decompress a single field (compressed JSON file) given the data has already been indexed in Splunk?

$
0
0
We have a compressed (via python zlib) JSON file that is "chunked" prior to being indexed by Splunk. The multiple events in Splunk (once indexed) can be pieced together (via Splunk's transaction command) yielding one event, containing multiple fields, one of which contains the compressed JSON file. How do we decompress this one field in Splunk given the data has already been indexed? (Decompressing earlier in the process, like during indexing, doesn't seem reasonable because data arrives in pieces due to various size limitations.) Thanks.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>