Hi all,
I have json data that incoming from FIREEYE but can't parsing.
I'm working with cluster environment.
inputs.conf on the heavy forwarder:
> Blockquote
[tcp://6012]
index=fire_eye
sourcetype=_json
disabled=0
> Blockquote
The events shown in Splunk but not parsing.
↧