<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to parse logs with a mix of JSON and non-JSON in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-logs-with-a-mix-of-JSON-and-non-JSON/m-p/569582#M101003</link>
    <description>&lt;P&gt;I made a few other corrections/assumptions about your sanitised example:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw="Oct 1 20:04:22 my-web01-aa-env my-web[14597]: app.NOTICE: Gateway Transaction Response (BP) {\"response\":\"&amp;lt;Auth&amp;gt;&amp;lt;Field1&amp;gt;ch-abcd1234-ab12-ab12-ab12-abcdef123456&amp;lt;/Field1&amp;gt;&amp;lt;Field2&amp;gt;0123&amp;lt;/Field2&amp;gt;&amp;lt;Field3&amp;gt;0123&amp;lt;/Field3&amp;gt;&amp;lt;Field4&amp;gt;Successful Request&amp;lt;/Field4&amp;gt;&amp;lt;responseMessage&amp;gt;&amp;lt;Field5&amp;gt;0123&amp;lt;/Field5&amp;gt;&amp;lt;Field6&amp;gt;0123&amp;lt;/Field6&amp;gt;&amp;lt;Field7&amp;gt;0123&amp;lt;/Field7&amp;gt;&amp;lt;Field8&amp;gt;0123&amp;lt;/Field8&amp;gt;&amp;lt;Field9&amp;gt;0123&amp;lt;/Field9&amp;gt;&amp;lt;Field10&amp;gt;0123&amp;lt;/Field10&amp;gt;&amp;lt;Field11&amp;gt;0123&amp;lt;/Field11&amp;gt;&amp;lt;Field12&amp;gt;0123&amp;lt;/Field12&amp;gt;&amp;lt;Field13&amp;gt;012 - Approved (APPROVAL 001077)&amp;lt;/Field13&amp;gt;&amp;lt;Field14&amp;gt;Approved: 012345 (approval code)&amp;lt;/Field14&amp;gt;&amp;lt;Field15&amp;gt;00000&amp;lt;/Field15&amp;gt;&amp;lt;Field16&amp;gt;Address not available (Address not verified)&amp;lt;/Field16&amp;gt;&amp;lt;Field17&amp;gt;40&amp;lt;/Field17&amp;gt;&amp;lt;Field18&amp;gt;&amp;lt;/Field18&amp;gt;&amp;lt;Field19&amp;gt;012345&amp;lt;/Field19&amp;gt;&amp;lt;Field20&amp;gt;20211001&amp;lt;/Field20&amp;gt;&amp;lt;Field21&amp;gt;0&amp;lt;/Field21&amp;gt;&amp;lt;Field22&amp;gt;840&amp;lt;/Field22&amp;gt;&amp;lt;Field23&amp;gt;USD&amp;lt;/Field23&amp;gt;&amp;lt;Field24&amp;gt;2021-10-01 16:04:21.493&amp;lt;/Field24&amp;gt;&amp;lt;Field25&amp;gt;2021-10-01 16:04:21.493&amp;lt;/Field25&amp;gt;&amp;lt;Field26&amp;gt;0123456&amp;lt;/Field26&amp;gt;&amp;lt;Field27&amp;gt;0123&amp;lt;/Field27&amp;gt;&amp;lt;Field28&amp;gt;0123456&amp;lt;/Field28&amp;gt;&amp;lt;Field29&amp;gt;0006&amp;lt;/Field29&amp;gt;&amp;lt;Field30&amp;gt;ABCDEF&amp;lt;/Field30&amp;gt;&amp;lt;Field31&amp;gt;Abc&amp;lt;/Field31&amp;gt;&amp;lt;Field32&amp;gt;ABC ABC ABC&amp;lt;/Field32&amp;gt;&amp;lt;Field33&amp;gt;Abcd&amp;lt;/Field33&amp;gt;&amp;lt;Field34&amp;gt;00&amp;lt;/Field34&amp;gt;&amp;lt;Field35&amp;gt;ABCDEF 012345 &amp;lt;/Field35&amp;gt;&amp;lt;Field36&amp;gt;ABCDEF0123&amp;lt;/Field36&amp;gt;&amp;lt;Field37&amp;gt;4F:A0000000041010;95:0000008000;9F10:0110A040002A0000000000000000000000FF;9B:E800;91:6325A37CFBC5CEDD0012;8A:&amp;lt;/Field37&amp;gt;&amp;lt;Field38&amp;gt;012345012345&amp;lt;/Field38&amp;gt;&amp;lt;Field39&amp;gt;abcd&amp;lt;/Field39&amp;gt;&amp;lt;Field40&amp;gt;False&amp;lt;/Field40&amp;gt;&amp;lt;Field40/&amp;gt;&amp;lt;Field41/&amp;gt;&amp;lt;Field42/&amp;gt;&amp;lt;Field43/&amp;gt;&amp;lt;Field44/&amp;gt;&amp;lt;/responseMessage&amp;gt;&amp;lt;/Auth&amp;gt;\"} []"



| rex "(?&amp;lt;datetime&amp;gt;\w+\s+\d+\s+\d\d:\d\d:\d\d)\s(?&amp;lt;server&amp;gt;[^\s]+)\s(?&amp;lt;process&amp;gt;[^\[]+)\[(?&amp;lt;pid&amp;gt;[^\]]+)\]:\s(?&amp;lt;variablefield&amp;gt;[^:]+):\s(?&amp;lt;variablevalue&amp;gt;[^\{]+)\s(?&amp;lt;json&amp;gt;\{[^\}]+\})\s\[\]"
| spath input=json
| spath input=response&lt;/LI-CODE&gt;</description>
    <pubDate>Mon, 04 Oct 2021 16:32:48 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2021-10-04T16:32:48Z</dc:date>
    <item>
      <title>How to parse logs with a mix of JSON and non-JSON</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-logs-with-a-mix-of-JSON-and-non-JSON/m-p/569569#M101000</link>
      <description>&lt;P&gt;Hi.&amp;nbsp; I have log source that has a mix of various field types and then a larger nested JSON payload.&amp;nbsp; I can't quite wrap my head around how to parse this out in our SplunkCloud environment.&lt;/P&gt;&lt;P&gt;High level, the log contains this:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;date field&lt;/LI&gt;&lt;LI&gt;server name field (separated by four dashes most of the time, but some env have three)&lt;/LI&gt;&lt;LI&gt;process name[PID]&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;source code function variable field ending with a colon char&lt;/LI&gt;&lt;LI&gt;source code function variable's value, which may or may not have special chars like ()&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;JSON&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;ends with []&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Sanitized example:&lt;/P&gt;&lt;P&gt;Oct 1 20:04:22 my-web01-aa-env my-web[14597]: app.NOTICE: Gateway Transaction Response (BP) {"response":"&amp;lt;Auth&amp;gt;&amp;lt;Field1&amp;gt;ch-abcd1234-ab12-ab12-ab12-abcdef123456&amp;lt;/Field1&amp;gt;&amp;lt;Field2&amp;gt;0123&amp;lt;/Field2&amp;gt;&amp;lt;Field3&amp;gt;0123&amp;lt;/Field3&amp;gt;&amp;lt;Field4&amp;gt;Successful Request&amp;lt;/Field4&amp;gt;&amp;lt;responseMessage&amp;gt;&amp;lt;Field5&amp;gt;0123&amp;lt;/Field5&amp;gt;&amp;lt;Field6&amp;gt;0123&amp;lt;/Field6&amp;gt;&amp;lt;Field7&amp;gt;0123&amp;lt;/Field7&amp;gt;&amp;lt;Field8&amp;gt;0123&amp;lt;/Field8&amp;gt;&amp;lt;Field9&amp;gt;0123&amp;lt;/Field9&amp;gt;&amp;lt;Field10&amp;gt;0123&amp;lt;/Field10&amp;gt;&amp;lt;Field11&amp;gt;0123&amp;lt;/Field11&amp;gt;&amp;lt;Field12&amp;gt;0123&amp;lt;/Field12&amp;gt;&amp;lt;Field13&amp;gt;012 - Approved (APPROVAL 001077)&amp;lt;/Field13&amp;gt;&amp;lt;Field14&amp;gt;Approved: 012345 (approval code)&amp;lt;/Field14&amp;gt;&amp;lt;Field15&amp;gt;00000&amp;lt;/Field15&amp;gt;&amp;lt;Field16&amp;gt;Address not available (Address not verified)&amp;lt;/Field16&amp;gt;&amp;lt;Field17&amp;gt;40&amp;lt;/Field17&amp;gt;&amp;lt;Field18&amp;gt;&amp;lt;/Field18&amp;gt;&amp;lt;Field19&amp;gt;012345&amp;lt;/Field19&amp;gt;&amp;lt;Field20&amp;gt;20211001&amp;lt;/Field20&amp;gt;&amp;lt;Field21&amp;gt;0&amp;lt;/Field21&amp;gt;&amp;lt;Field22&amp;gt;840&amp;lt;/Field22&amp;gt;&amp;lt;Field23&amp;gt;USD&amp;lt;/Field23&amp;gt;&amp;lt;Field24&amp;gt;2021-10-01 16:04:21.493&amp;lt;/Field24&amp;gt;&amp;lt;Field25&amp;gt;2021-10-01 16:04:21.493&amp;lt;/Field25&amp;gt;&amp;lt;Field26&amp;gt;0123456&amp;lt;/Field26&amp;gt;&amp;lt;Field27&amp;gt;0123&amp;lt;/Field27&amp;gt;&amp;lt;Field28&amp;gt;0123456&amp;lt;/Field28&amp;gt;&amp;lt;Field29&amp;gt;0006&amp;lt;/Field29&amp;gt;&amp;lt;Field30&amp;gt;ABCDEF&amp;lt;/Field30&amp;gt;&amp;lt;Field31&amp;gt;Abc&amp;lt;/Field31&amp;gt;&amp;lt;Field32&amp;gt;ABC ABC ABC&amp;lt;/Field32&amp;gt;&amp;lt;Field33&amp;gt;Abcd&amp;lt;/Field33&amp;gt;&amp;lt;Field34&amp;gt;00&amp;lt;/Field34&amp;gt;&amp;lt;Field35&amp;gt;ABCDEF 012345 &amp;lt;/Field35&amp;gt;&amp;lt;Field36&amp;gt;ABCDEF0123&amp;lt;/Field36&amp;gt;&amp;lt;Field37&amp;gt;4F:A0000000041010;95:0000008000;9F10:0110A040002A0000000000000000000000FF;9B:E800;91:6325A37CFBC5CEDD0012;8A:&amp;lt;/Field37&amp;gt;&amp;lt;Field38&amp;gt;012345012345&amp;lt;/Field38&amp;gt;&amp;lt;Field39&amp;gt;abcd&amp;lt;/Field38&amp;gt;&amp;lt;Field39&amp;gt;False&amp;lt;/Field39&amp;gt;&amp;lt;Field40 /&amp;gt;&amp;lt;Field40 /&amp;gt;&amp;lt;Field41 /&amp;gt;&amp;lt;Field42 /&amp;gt;&amp;lt;Field42 /&amp;gt;&amp;lt;/Field43&amp;gt;&amp;lt;/Field43&amp;gt;"} []&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My grok-fu is not great.&amp;nbsp; Would appreciate any suggestions.&amp;nbsp; Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 15:23:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-logs-with-a-mix-of-JSON-and-non-JSON/m-p/569569#M101000</guid>
      <dc:creator>khenson</dc:creator>
      <dc:date>2021-10-04T15:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to parse logs with a mix of JSON and non-JSON</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-logs-with-a-mix-of-JSON-and-non-JSON/m-p/569574#M101001</link>
      <description>&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw="Oct 1 20:04:22 my-web01-aa-env my-web[14597]: app.NOTICE: Gateway Transaction Response (BP) {\"response\":\"&amp;lt;Auth&amp;gt;&amp;lt;Field1&amp;gt;ch-abcd1234-ab12-ab12-ab12-abcdef123456&amp;lt;/Field1&amp;gt;&amp;lt;Field2&amp;gt;0123&amp;lt;/Field2&amp;gt;&amp;lt;Field3&amp;gt;0123&amp;lt;/Field3&amp;gt;&amp;lt;Field4&amp;gt;Successful Request&amp;lt;/Field4&amp;gt;&amp;lt;responseMessage&amp;gt;&amp;lt;Field5&amp;gt;0123&amp;lt;/Field5&amp;gt;&amp;lt;Field6&amp;gt;0123&amp;lt;/Field6&amp;gt;&amp;lt;Field7&amp;gt;0123&amp;lt;/Field7&amp;gt;&amp;lt;Field8&amp;gt;0123&amp;lt;/Field8&amp;gt;&amp;lt;Field9&amp;gt;0123&amp;lt;/Field9&amp;gt;&amp;lt;Field10&amp;gt;0123&amp;lt;/Field10&amp;gt;&amp;lt;Field11&amp;gt;0123&amp;lt;/Field11&amp;gt;&amp;lt;Field12&amp;gt;0123&amp;lt;/Field12&amp;gt;&amp;lt;Field13&amp;gt;012 - Approved (APPROVAL 001077)&amp;lt;/Field13&amp;gt;&amp;lt;Field14&amp;gt;Approved: 012345 (approval code)&amp;lt;/Field14&amp;gt;&amp;lt;Field15&amp;gt;00000&amp;lt;/Field15&amp;gt;&amp;lt;Field16&amp;gt;Address not available (Address not verified)&amp;lt;/Field16&amp;gt;&amp;lt;Field17&amp;gt;40&amp;lt;/Field17&amp;gt;&amp;lt;Field18&amp;gt;&amp;lt;/Field18&amp;gt;&amp;lt;Field19&amp;gt;012345&amp;lt;/Field19&amp;gt;&amp;lt;Field20&amp;gt;20211001&amp;lt;/Field20&amp;gt;&amp;lt;Field21&amp;gt;0&amp;lt;/Field21&amp;gt;&amp;lt;Field22&amp;gt;840&amp;lt;/Field22&amp;gt;&amp;lt;Field23&amp;gt;USD&amp;lt;/Field23&amp;gt;&amp;lt;Field24&amp;gt;2021-10-01 16:04:21.493&amp;lt;/Field24&amp;gt;&amp;lt;Field25&amp;gt;2021-10-01 16:04:21.493&amp;lt;/Field25&amp;gt;&amp;lt;Field26&amp;gt;0123456&amp;lt;/Field26&amp;gt;&amp;lt;Field27&amp;gt;0123&amp;lt;/Field27&amp;gt;&amp;lt;Field28&amp;gt;0123456&amp;lt;/Field28&amp;gt;&amp;lt;Field29&amp;gt;0006&amp;lt;/Field29&amp;gt;&amp;lt;Field30&amp;gt;ABCDEF&amp;lt;/Field30&amp;gt;&amp;lt;Field31&amp;gt;Abc&amp;lt;/Field31&amp;gt;&amp;lt;Field32&amp;gt;ABC ABC ABC&amp;lt;/Field32&amp;gt;&amp;lt;Field33&amp;gt;Abcd&amp;lt;/Field33&amp;gt;&amp;lt;Field34&amp;gt;00&amp;lt;/Field34&amp;gt;&amp;lt;Field35&amp;gt;ABCDEF 012345 &amp;lt;/Field35&amp;gt;&amp;lt;Field36&amp;gt;ABCDEF0123&amp;lt;/Field36&amp;gt;&amp;lt;Field37&amp;gt;4F:A0000000041010;95:0000008000;9F10:0110A040002A0000000000000000000000FF;9B:E800;91:6325A37CFBC5CEDD0012;8A:&amp;lt;/Field37&amp;gt;&amp;lt;Field38&amp;gt;012345012345&amp;lt;/Field38&amp;gt;&amp;lt;Field39&amp;gt;abcd&amp;lt;/Field38&amp;gt;&amp;lt;Field39&amp;gt;False&amp;lt;/Field39&amp;gt;&amp;lt;Field40 /&amp;gt;&amp;lt;Field40 /&amp;gt;&amp;lt;Field41 /&amp;gt;&amp;lt;Field42 /&amp;gt;&amp;lt;Field42 /&amp;gt;&amp;lt;/Field43&amp;gt;&amp;lt;/Field43&amp;gt;\"} []"



| rex "(?&amp;lt;datetime&amp;gt;\w+\s+\d+\s+\d\d:\d\d:\d\d)\s(?&amp;lt;server&amp;gt;[^\s]+)\s(?&amp;lt;process&amp;gt;[^\[]+)\[(?&amp;lt;pid&amp;gt;[^\]]+)\]:\s(?&amp;lt;variablefield&amp;gt;[^:]+):\s(?&amp;lt;variablevalue&amp;gt;[^\{]+)\s(?&amp;lt;json&amp;gt;\{[^\}]+\})\s\[\]"&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 04 Oct 2021 15:42:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-logs-with-a-mix-of-JSON-and-non-JSON/m-p/569574#M101001</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-10-04T15:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to parse logs with a mix of JSON and non-JSON</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-logs-with-a-mix-of-JSON-and-non-JSON/m-p/569581#M101002</link>
      <description>&lt;P&gt;I see an error in my sanitized log, the last &amp;lt;/Field43&amp;gt; should have been &amp;lt;/Auth&amp;gt;.&amp;nbsp;&amp;nbsp;This seems pretty close, but the JSON didn't appear to show up as separate fields.&amp;nbsp; I was thinking that the JSON could be parsed into:&lt;BR /&gt;response.Auth.Field1&lt;/P&gt;&lt;P&gt;respoonse.Auth.Field2&lt;/P&gt;&lt;P&gt;Does that make sense?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 16:19:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-logs-with-a-mix-of-JSON-and-non-JSON/m-p/569581#M101002</guid>
      <dc:creator>khenson</dc:creator>
      <dc:date>2021-10-04T16:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to parse logs with a mix of JSON and non-JSON</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-logs-with-a-mix-of-JSON-and-non-JSON/m-p/569582#M101003</link>
      <description>&lt;P&gt;I made a few other corrections/assumptions about your sanitised example:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw="Oct 1 20:04:22 my-web01-aa-env my-web[14597]: app.NOTICE: Gateway Transaction Response (BP) {\"response\":\"&amp;lt;Auth&amp;gt;&amp;lt;Field1&amp;gt;ch-abcd1234-ab12-ab12-ab12-abcdef123456&amp;lt;/Field1&amp;gt;&amp;lt;Field2&amp;gt;0123&amp;lt;/Field2&amp;gt;&amp;lt;Field3&amp;gt;0123&amp;lt;/Field3&amp;gt;&amp;lt;Field4&amp;gt;Successful Request&amp;lt;/Field4&amp;gt;&amp;lt;responseMessage&amp;gt;&amp;lt;Field5&amp;gt;0123&amp;lt;/Field5&amp;gt;&amp;lt;Field6&amp;gt;0123&amp;lt;/Field6&amp;gt;&amp;lt;Field7&amp;gt;0123&amp;lt;/Field7&amp;gt;&amp;lt;Field8&amp;gt;0123&amp;lt;/Field8&amp;gt;&amp;lt;Field9&amp;gt;0123&amp;lt;/Field9&amp;gt;&amp;lt;Field10&amp;gt;0123&amp;lt;/Field10&amp;gt;&amp;lt;Field11&amp;gt;0123&amp;lt;/Field11&amp;gt;&amp;lt;Field12&amp;gt;0123&amp;lt;/Field12&amp;gt;&amp;lt;Field13&amp;gt;012 - Approved (APPROVAL 001077)&amp;lt;/Field13&amp;gt;&amp;lt;Field14&amp;gt;Approved: 012345 (approval code)&amp;lt;/Field14&amp;gt;&amp;lt;Field15&amp;gt;00000&amp;lt;/Field15&amp;gt;&amp;lt;Field16&amp;gt;Address not available (Address not verified)&amp;lt;/Field16&amp;gt;&amp;lt;Field17&amp;gt;40&amp;lt;/Field17&amp;gt;&amp;lt;Field18&amp;gt;&amp;lt;/Field18&amp;gt;&amp;lt;Field19&amp;gt;012345&amp;lt;/Field19&amp;gt;&amp;lt;Field20&amp;gt;20211001&amp;lt;/Field20&amp;gt;&amp;lt;Field21&amp;gt;0&amp;lt;/Field21&amp;gt;&amp;lt;Field22&amp;gt;840&amp;lt;/Field22&amp;gt;&amp;lt;Field23&amp;gt;USD&amp;lt;/Field23&amp;gt;&amp;lt;Field24&amp;gt;2021-10-01 16:04:21.493&amp;lt;/Field24&amp;gt;&amp;lt;Field25&amp;gt;2021-10-01 16:04:21.493&amp;lt;/Field25&amp;gt;&amp;lt;Field26&amp;gt;0123456&amp;lt;/Field26&amp;gt;&amp;lt;Field27&amp;gt;0123&amp;lt;/Field27&amp;gt;&amp;lt;Field28&amp;gt;0123456&amp;lt;/Field28&amp;gt;&amp;lt;Field29&amp;gt;0006&amp;lt;/Field29&amp;gt;&amp;lt;Field30&amp;gt;ABCDEF&amp;lt;/Field30&amp;gt;&amp;lt;Field31&amp;gt;Abc&amp;lt;/Field31&amp;gt;&amp;lt;Field32&amp;gt;ABC ABC ABC&amp;lt;/Field32&amp;gt;&amp;lt;Field33&amp;gt;Abcd&amp;lt;/Field33&amp;gt;&amp;lt;Field34&amp;gt;00&amp;lt;/Field34&amp;gt;&amp;lt;Field35&amp;gt;ABCDEF 012345 &amp;lt;/Field35&amp;gt;&amp;lt;Field36&amp;gt;ABCDEF0123&amp;lt;/Field36&amp;gt;&amp;lt;Field37&amp;gt;4F:A0000000041010;95:0000008000;9F10:0110A040002A0000000000000000000000FF;9B:E800;91:6325A37CFBC5CEDD0012;8A:&amp;lt;/Field37&amp;gt;&amp;lt;Field38&amp;gt;012345012345&amp;lt;/Field38&amp;gt;&amp;lt;Field39&amp;gt;abcd&amp;lt;/Field39&amp;gt;&amp;lt;Field40&amp;gt;False&amp;lt;/Field40&amp;gt;&amp;lt;Field40/&amp;gt;&amp;lt;Field41/&amp;gt;&amp;lt;Field42/&amp;gt;&amp;lt;Field43/&amp;gt;&amp;lt;Field44/&amp;gt;&amp;lt;/responseMessage&amp;gt;&amp;lt;/Auth&amp;gt;\"} []"



| rex "(?&amp;lt;datetime&amp;gt;\w+\s+\d+\s+\d\d:\d\d:\d\d)\s(?&amp;lt;server&amp;gt;[^\s]+)\s(?&amp;lt;process&amp;gt;[^\[]+)\[(?&amp;lt;pid&amp;gt;[^\]]+)\]:\s(?&amp;lt;variablefield&amp;gt;[^:]+):\s(?&amp;lt;variablevalue&amp;gt;[^\{]+)\s(?&amp;lt;json&amp;gt;\{[^\}]+\})\s\[\]"
| spath input=json
| spath input=response&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 04 Oct 2021 16:32:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-logs-with-a-mix-of-JSON-and-non-JSON/m-p/569582#M101003</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-10-04T16:32:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to parse logs with a mix of JSON and non-JSON</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-logs-with-a-mix-of-JSON-and-non-JSON/m-p/569583#M101004</link>
      <description>&lt;P&gt;Thank you very much for your time and sharing this.&amp;nbsp; I will start looking at how to incorporate this in my sourcetype in SplunkCloud.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 16:44:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-logs-with-a-mix-of-JSON-and-non-JSON/m-p/569583#M101004</guid>
      <dc:creator>khenson</dc:creator>
      <dc:date>2021-10-04T16:44:16Z</dc:date>
    </item>
  </channel>
</rss>

