I'm having trouble getting the JSON under the "message" field recognized in splunk. Is there something simple I'm missing on the Cribl side of things to break this json out of message, or only keep the JSON in the message as the event?
Question
Passing the message field in JSON to Splunk
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
