Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to make index-time field extraction work for REST API receiver input?

$
0
0
I have `INDEXED_EXTRACTIONS = json` and `TIMESTAMP_FIELDS = my_timestamp_field` in [my_json_type] stanza. This works when I upload a file and select my_json_type as source type. But when I post the exact same data via REST API's receiver endpoint, no field extraction happens. (Both datasets returned by search *sourcetype=my_json_type*.) How can I make this work for both file upload and REST API?

Viewing all articles
Browse latest Browse all 47296

Trending Articles