We have updated our Terms of Service, Code of Conduct, and Addendum.

Passing the message field in JSON to Splunk

Options

I'm having trouble getting the JSON under the "message" field recognized in splunk. Is there something simple I'm missing on the Cribl side of things to break this json out of message, or only keep the JSON in the message as the event?

Answers