Hello, Thank you for your help, I appreciate. I m trying to explain what I want 1. We send json logs to a Mysql DB from an application server -> this is the logs format from the application server --> {"bam":{"facture":{"@idFFFFF":"","@idBBBBB":"","@idCCCCC":"","@idCCCCC":"","@ABCACB":"","@status":""},"Contact":{"@idContact":"","@nom":"","@prenom":"","@adresse":"","@typeContact":""},"service":{"@jobName":"XX_Abcdef_Abccc_Token_V1","@jobVersion":"x.x","@routeName":"","@routeVersion":"","@currentTime":"2023-07-03 13:00:28","@idCorrelation":"545454ssss-abcc-456ss-5454-444455555554444","@serviceDuration":"1140"}}} If I copy this ligne on notepad and manually import it on splunk I get want I want to have (I used the default source type) Each value is extracted so it's perfect 2. To automatiquely get the new logs from the DB server I decided to use Splunk DB connect ( maybe it's not the best choice ? ) So I configured a new input in the Splunk DB connect to get the value from the DB table But now the data are not indexed on json format as shown below How can I get these datas on json format as shown on the first and second capture ? Hope iyou understand better what I m trying to do Regards,
... View more