Skip to main content
Question

How do I prevent the double underscore internal Cribl fields from being inserted into the _raw?

  • March 11, 2025
  • 7 replies
  • 20 views

I'm trying to serialize into JSON and just keep the _raw field left over after bringing all the fields together. How do I prevent the double underscore internal Cribl fields from being inserted into the _raw field I'm creating?

7 replies


  • Author
  • Employee
  • March 11, 2025

It didn't seem to work within the serializing function. I had to add an eval before the serialize and explicitly remove all double underscore fields that way


  • Author
  • Employee
  • March 11, 2025

Kind of annoying


  • Author
  • Employee
  • March 11, 2025

Since I'm not seeing them until I forward them to Splunk. They don't show up in my previews of my log samples


Jon Rust
Forum|alt.badge.img
  • Employee
  • March 11, 2025

in the fields to serialize field:`!* !cribl* *`


  • Author
  • Employee
  • March 11, 2025

I see now. I had the wildcard first but you need to put all excludes first.


Jon Rust
Forum|alt.badge.img
  • Employee
  • March 11, 2025

yep! let me know how it goes