Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do I get Splunk to recognize and parse one of my field values in JSON format?

$
0
0
I have perfect key/value pairs in my log (I am using the Splunk Add-on for Microsoft Azure to get table storage logs). The logs have: LogTyppe: LogTyppe MessageDetail: {"test"="this will work", "name"="value", "name1"="value1", "name2"="value2"} MessageSummary: MessageSummary NetworkAddress: NetworkAddress Notice in MessageDetail there is a JSON formatted string... How do I get Splunk to recognize that one of the field values as json format?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>