<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Work with fieldnames that contains {}. +PRTG in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/554065#M5970</link>
    <description>Hi&lt;BR /&gt;as your event is json, you should try spath with it.&lt;BR /&gt;r. Ismo</description>
    <pubDate>Wed, 02 Jun 2021 08:19:25 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2021-06-02T08:19:25Z</dc:date>
    <item>
      <title>Work with fieldnames that contains {}. +PRTG</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/553833#M5958</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm using the PRTG app to get logs from this monitoring tool and build clean reports about our servers health.&lt;/P&gt;&lt;P&gt;The API is returning a JSON and the automatic field extraction gets fields like&amp;nbsp;sensors{}.sensor.&lt;/P&gt;&lt;P&gt;How could I build a query referencing to this fields? If I try something like this fails:&lt;/P&gt;&lt;P&gt;index=prtg "sensors{}.sensor"=Ping&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 11:09:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/553833#M5958</guid>
      <dc:creator>maaneeel</dc:creator>
      <dc:date>2021-06-01T11:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: Work with fieldnames that contains {}. +PRTG</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/553837#M5959</link>
      <description>&lt;P&gt;Try with single quotes not double&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index=prtg 'sensors{}.sensor'=Ping&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 11:50:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/553837#M5959</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-01T11:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: Work with fieldnames that contains {}. +PRTG</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/553976#M5961</link>
      <description>Exactly that way. Usually single quote means field and double means value (of field).</description>
      <pubDate>Tue, 01 Jun 2021 21:22:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/553976#M5961</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-06-01T21:22:32Z</dc:date>
    </item>
    <item>
      <title>Re: Work with fieldnames that contains {}. +PRTG</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/554054#M5968</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk_query.png" style="width: 713px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14430i648DE9D3CDB3A242/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunk_query.png" alt="splunk_query.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Hello again, It's not working,&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 07:13:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/554054#M5968</guid>
      <dc:creator>maaneeel</dc:creator>
      <dc:date>2021-06-02T07:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: Work with fieldnames that contains {}. +PRTG</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/554056#M5969</link>
      <description>&lt;P class="lia-align-left"&gt;I also tried use eval and filter by the new result without success&lt;/P&gt;&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eval.png" style="width: 801px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14431i22EA5BBC4943757E/image-size/large?v=v2&amp;amp;px=999" role="button" title="eval.png" alt="eval.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 07:20:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/554056#M5969</guid>
      <dc:creator>maaneeel</dc:creator>
      <dc:date>2021-06-02T07:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: Work with fieldnames that contains {}. +PRTG</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/554065#M5970</link>
      <description>Hi&lt;BR /&gt;as your event is json, you should try spath with it.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Wed, 02 Jun 2021 08:19:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/554065#M5970</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-06-02T08:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Work with fieldnames that contains {}. +PRTG</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/554078#M5973</link>
      <description>&lt;P&gt;It looks like sensors{}.sensor is a multi-value field - try extracting the collection (spath) and separate each element into different events (mvexpand), then extract the fields you are interested in (spath again).&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 09:42:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/554078#M5973</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-02T09:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: Work with fieldnames that contains {}. +PRTG</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/554083#M5974</link>
      <description>&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didn't know spath command, but after try it I have the same problem with the new field...&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="spath.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14434iF36DCC0760BAC38E/image-size/large?v=v2&amp;amp;px=999" role="button" title="spath.png" alt="spath.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 10:15:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/554083#M5974</guid>
      <dc:creator>maaneeel</dc:creator>
      <dc:date>2021-06-02T10:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: Work with fieldnames that contains {}. +PRTG</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/554086#M5975</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=prtg
| spath output=sensors path=sensors{}
| mvexpand sensors
| search Ping
| spath input=sensors&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 02 Jun 2021 10:54:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Work-with-fieldnames-that-contains-PRTG/m-p/554086#M5975</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-02T10:54:05Z</dc:date>
    </item>
  </channel>
</rss>

