今天才检查一个case 的时候,发现: /opt/splunk/var/log/splunk/splunkd.log 里面有报错:
parsing error:Unexpected character while looking for value: '}' - data
下面是一些调查:
Splunk not ingesting JSON data and generating JsonLineBreaker errors in Splunkd logs.
The source data is malformed which keeps Splunk from parsing and ingesting the events correctly.
Description
A specific data input stopped ingesting data.
The following error is in the splunkd log of the instance that is parsing the events:
ERROR JsonLineBreaker - JSON StreamId:12768491381919637733 had parsing error:Unexpected character: ':' - d