Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fixes sourcetype to properly parse json data #11

Merged
merged 1 commit into from
Oct 28, 2024
Merged

Conversation

markkasaboski
Copy link
Collaborator

@markkasaboski markkasaboski commented Oct 28, 2024

  • Removes index=flare from inputs.conf so now all data will be sent to the "main" index.
  • Changes source to "Flare" so that events are easily searched for using index="main" source="Flare"
  • Fixes sourcetype as it should be a "pretrained" Splunk type. Changed to json_no_timestamp and this now parses the json correctly and is now readable.
Screenshot 2024-10-28 at 1 13 01 PM

@markkasaboski markkasaboski requested a review from TyMarc October 28, 2024 17:18
@markkasaboski markkasaboski self-assigned this Oct 28, 2024
Copy link
Contributor

@TyMarc TyMarc left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@markkasaboski markkasaboski merged commit bf4a96c into main Oct 28, 2024
2 checks passed
@markkasaboski markkasaboski deleted the mark/format-data branch October 28, 2024 18:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants