Default Version 0.3.0
March 29, 2021
March 29, 2021
Splunk Enterprise
Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0
Log in to rate this app
Splunk can export events in JSON via the web interface and when queried via the REST api can return JSON output. It can also parse JSON at index/search-time, but it can't *create* JSON at search-time. This app provides a 'mkjson' command that can create a JSON field from a given list or all fields in an event. For usage, please see the documentation: https://github.com/doksu/TA-jsontools/wiki
Log in to report this app listing.