<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: To get the values of a particular fields in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-the-values-of-a-particular-fields/m-p/638314#M15916</link>
    <description>&lt;LI-CODE lang="markup"&gt;| spath input=request&lt;/LI-CODE&gt;</description>
    <pubDate>Mon, 03 Apr 2023 07:18:05 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2023-04-03T07:18:05Z</dc:date>
    <item>
      <title>How to get the values of a particular fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-the-values-of-a-particular-fields/m-p/638311#M15915</link>
      <description>&lt;P&gt;Like how to extract the values of country and channel id for the dashboard, right when I'm pulling it. I'm getting both Country id and channel id in one column, but I want to segregate both individuals columns in dashboards.&lt;/P&gt;
&lt;P&gt;I've below sample event type:&amp;nbsp;Path= /Verify/ endpoint request={"userId":"xxxxxxxxxxxxxxxxx","country":"AB","channelId":"111111","ssnNumber":null,"operatorId":"test"} response={"result":"ERROR","error_reason":"NO_DATA_ERROR","error_category":"APPLICATION","error_text":"No for user exist","error_rc":444}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please suggest..&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 01:53:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-the-values-of-a-particular-fields/m-p/638311#M15915</guid>
      <dc:creator>eprpradeep</dc:creator>
      <dc:date>2023-04-04T01:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: To get the values of a particular fields</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-the-values-of-a-particular-fields/m-p/638314#M15916</link>
      <description>&lt;LI-CODE lang="markup"&gt;| spath input=request&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 03 Apr 2023 07:18:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-the-values-of-a-particular-fields/m-p/638314#M15916</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-04-03T07:18:05Z</dc:date>
    </item>
  </channel>
</rss>

