Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Indexing JSON - problem

$
0
0
Hi all, I have json data that incoming from FIREEYE but can't parsing. I'm working with cluster environment. inputs.conf on the heavy forwarder: > Blockquote [tcp://6012] index=fire_eye sourcetype=_json disabled=0 > Blockquote The events shown in Splunk but not parsing.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>