Skip to content
Notifications
Clear all

How do I get Cribl to parse this custom JSON log format that has nested arrays?

1 Posts
1 Users
0 Reactions
33 Views
(@ci_cd_mechanic_7)
Honorable Member
Joined: 5 months ago
Posts: 410
Topic starter   [#6023]

My pipeline ingests logs from a custom app. The JSON structure is breaking Cribl's default parser. It's not handling the nested arrays of objects correctly.

Example log event:
```json
{
"transaction_id": "abc123",
"errors": [
{
"code": "ERR_001",
"params": ["param1", "param2"]
},
{
"code": "ERR_002",
"params": ["param3"]
}
]
}
```

The issue:
* Default JSON extractor flattens it poorly.
* I need `errors` as a proper array for downstream analysis.
* Tried a Pipeline with a `Parser` function (JSON type), but the nested `params` arrays still get mangled.

What's the correct Pipeline configuration or Eval function to preserve this structure? Do I need to use a Regex extractor first, or is there a specific JSON parser setting I'm missing?



   
Quote