I'm sending JSON data to Splunk from cribl (Cloudflare logs) and it causes the data to be a horrendous .30:1 index size to raw size ratio I'm sending _raw as text. There are no props for that sourcetype on the indexer side so there is no indexed extractions. Any help appreciated
Question
Sending JSON data to Splunk from Cribl causing.30:1
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
