<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Need help parsing and extracting MongoDB JSON log in Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-parsing-and-extracting-MongoDB-JSON-log-in-Splunk/m-p/594428#M103903</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I need some help.&lt;/P&gt;&lt;P&gt;We have been using Splunk for MongoDB alert for a while, now the new MongoDB version we are upgrading to is changing the log format from text to JSON.&lt;/P&gt;&lt;P&gt;I need to alter the alert in Splunk so that it will continue to work with the new JSON log format.&lt;/P&gt;&lt;P&gt;Here is an example of a search query in one of the alert we have now:&lt;/P&gt;&lt;P&gt;index=googlecloud*&lt;BR /&gt;source="projects/dir1/dir2/mongodblogs"&lt;BR /&gt;data.logName="projects/dir3/logs/mongodb"&lt;BR /&gt;data.textPayload="* REPL *"&lt;BR /&gt;NOT "catchup takeover"&lt;BR /&gt;| rex field=&lt;STRONG&gt;&lt;FONT face="times new roman,times"&gt;data.textPayload "(?&amp;lt;sourceTimestamp&amp;gt;\d{4}-\d*-\d*T\d*:\d*:\d*.\d*)-\d*\s*(?&amp;lt;severity&amp;gt;\w*)\s*(?&amp;lt;component&amp;gt;\w*)\s*(?&amp;lt;context&amp;gt;\S*)\s*(?&amp;lt;message&amp;gt;.*)"&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;| search component="REPL"&lt;BR /&gt;message!="*took *ms"&lt;BR /&gt;message!="warning: log line attempted * over max size*"&lt;BR /&gt;NOT (severity="I" AND message="applied op: CRUD*" AND message!="*took *ms")&lt;BR /&gt;| rename data.labels.compute.googleapis.com/resource_name as server&lt;BR /&gt;| regex server="^preprod0[12]-.+-mongodb-server8*\d$"&lt;BR /&gt;| sort sourceTimestamp data.insertId&lt;BR /&gt;| table sourceTimestamp server severity component context message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The content of the MongoDB log is under data.TextPayload, currently is being formatted using regex and split into 5 groups with labels and then we search from each group for the string or message that we want to be alerted on.&lt;/P&gt;&lt;P&gt;The new JSON format log looks like this:&lt;/P&gt;&lt;P&gt;{"t":{"$date":"2022-04-19T07:50:31.005-04:00"},"s":"I", "c":"REPL", "id":21340, "ctx":"RstlKillOpThread","msg":"State transition ops metrics","attr":{"metrics":{"lastStateTransition":"stepDown","userOpsKilled":0,"userOpsRunning":4}}}&lt;/P&gt;&lt;P&gt;I need to split them into 7 groups, using comma as delimiter and then search from each group using the same search criteria.&lt;/P&gt;&lt;P&gt;I have been trying and testing for 2 days, I'm new to Splunk and not very good in regex.&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;&lt;P&gt;Sally&lt;/P&gt;</description>
    <pubDate>Wed, 20 Apr 2022 11:07:29 GMT</pubDate>
    <dc:creator>ychoo</dc:creator>
    <dc:date>2022-04-20T11:07:29Z</dc:date>
    <item>
      <title>Need help parsing and extracting MongoDB JSON log in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-parsing-and-extracting-MongoDB-JSON-log-in-Splunk/m-p/594428#M103903</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I need some help.&lt;/P&gt;&lt;P&gt;We have been using Splunk for MongoDB alert for a while, now the new MongoDB version we are upgrading to is changing the log format from text to JSON.&lt;/P&gt;&lt;P&gt;I need to alter the alert in Splunk so that it will continue to work with the new JSON log format.&lt;/P&gt;&lt;P&gt;Here is an example of a search query in one of the alert we have now:&lt;/P&gt;&lt;P&gt;index=googlecloud*&lt;BR /&gt;source="projects/dir1/dir2/mongodblogs"&lt;BR /&gt;data.logName="projects/dir3/logs/mongodb"&lt;BR /&gt;data.textPayload="* REPL *"&lt;BR /&gt;NOT "catchup takeover"&lt;BR /&gt;| rex field=&lt;STRONG&gt;&lt;FONT face="times new roman,times"&gt;data.textPayload "(?&amp;lt;sourceTimestamp&amp;gt;\d{4}-\d*-\d*T\d*:\d*:\d*.\d*)-\d*\s*(?&amp;lt;severity&amp;gt;\w*)\s*(?&amp;lt;component&amp;gt;\w*)\s*(?&amp;lt;context&amp;gt;\S*)\s*(?&amp;lt;message&amp;gt;.*)"&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;| search component="REPL"&lt;BR /&gt;message!="*took *ms"&lt;BR /&gt;message!="warning: log line attempted * over max size*"&lt;BR /&gt;NOT (severity="I" AND message="applied op: CRUD*" AND message!="*took *ms")&lt;BR /&gt;| rename data.labels.compute.googleapis.com/resource_name as server&lt;BR /&gt;| regex server="^preprod0[12]-.+-mongodb-server8*\d$"&lt;BR /&gt;| sort sourceTimestamp data.insertId&lt;BR /&gt;| table sourceTimestamp server severity component context message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The content of the MongoDB log is under data.TextPayload, currently is being formatted using regex and split into 5 groups with labels and then we search from each group for the string or message that we want to be alerted on.&lt;/P&gt;&lt;P&gt;The new JSON format log looks like this:&lt;/P&gt;&lt;P&gt;{"t":{"$date":"2022-04-19T07:50:31.005-04:00"},"s":"I", "c":"REPL", "id":21340, "ctx":"RstlKillOpThread","msg":"State transition ops metrics","attr":{"metrics":{"lastStateTransition":"stepDown","userOpsKilled":0,"userOpsRunning":4}}}&lt;/P&gt;&lt;P&gt;I need to split them into 7 groups, using comma as delimiter and then search from each group using the same search criteria.&lt;/P&gt;&lt;P&gt;I have been trying and testing for 2 days, I'm new to Splunk and not very good in regex.&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;&lt;P&gt;Sally&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 11:07:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-help-parsing-and-extracting-MongoDB-JSON-log-in-Splunk/m-p/594428#M103903</guid>
      <dc:creator>ychoo</dc:creator>
      <dc:date>2022-04-20T11:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Need help parsing and extracting MongoDB JSON log in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-parsing-and-extracting-MongoDB-JSON-log-in-Splunk/m-p/594434#M103904</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245055"&gt;@ychoo&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I think you'll need to update the sourcetype for the log from text to json to correctly parse the logs looking at a good long term solution.&lt;BR /&gt;If not you can proceed with using spath or regex for field extractions.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gr0und_Z3r0_0-1650453605845.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19147i0528D074B1AB03E1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gr0und_Z3r0_0-1650453605845.png" alt="Gr0und_Z3r0_0-1650453605845.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;source="D:\\Learn Splunk\\test.txt"  sourcetype="text"
| rex field=_raw "date\"\:\"(?P&amp;lt;SourceTimestamp&amp;gt;[\d\-\:\.T]+)\"\},\"s\"\:\"(?P&amp;lt;Severity&amp;gt;[\w]+)\",\s\"c\"\:\"(?P&amp;lt;Component&amp;gt;[\w]+)"
| rex field=_raw "ctx\"\:\"(?P&amp;lt;Context&amp;gt;[\w]+)\",\"msg\"\:\"(?P&amp;lt;Message&amp;gt;[\w\s]+)"
| table _time SourceTimestamp Severity Component Context Message&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gr0und_Z3r0_2-1650454407007.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19149i0B4AD8B18EE79C67/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gr0und_Z3r0_2-1650454407007.png" alt="Gr0und_Z3r0_2-1650454407007.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 11:33:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-help-parsing-and-extracting-MongoDB-JSON-log-in-Splunk/m-p/594434#M103904</guid>
      <dc:creator>Gr0und_Z3r0</dc:creator>
      <dc:date>2022-04-20T11:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: Need help parsing and extracting MongoDB JSON log in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-parsing-and-extracting-MongoDB-JSON-log-in-Splunk/m-p/594834#M103946</link>
      <description>&lt;P&gt;I got this one working now with below:&lt;/P&gt;&lt;P&gt;sourcetype=json&lt;BR /&gt;| spath input="data.textPayload" output="Timestamp" path=t&lt;BR /&gt;| spath input="data.textPayload" output="Severity" path=s&lt;BR /&gt;| spath input="data.textPayload" output="Component" path=c&lt;BR /&gt;| spath input="data.textPayload" output="Context" path=ctx&lt;BR /&gt;| spath input="data.textPayload" output="Message" path=msg&lt;BR /&gt;| spath input="data.textPayload" output="Attr" path=attr&lt;/P&gt;&lt;P&gt;| search &amp;lt; Search criteria by field here&amp;gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;| table Timestamp Server Severity Component Context Message Attr&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 11:18:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-help-parsing-and-extracting-MongoDB-JSON-log-in-Splunk/m-p/594834#M103946</guid>
      <dc:creator>ychoo</dc:creator>
      <dc:date>2022-04-22T11:18:30Z</dc:date>
    </item>
  </channel>
</rss>

