<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Help with Table Format - JSON in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-Table-Format-JSON/m-p/628047#M107773</link>
    <description>&lt;P&gt;performing the following search:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JCANDIAT_0-1674510125746.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23500i8F3816A6C5B20A51/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JCANDIAT_0-1674510125746.png" alt="JCANDIAT_0-1674510125746.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I get this result. I need to parser this information, building a table excel type. The information is in JSON format, so a UPLOAD in SPLUNK.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JCANDIAT_2-1674510242190.png" style="width: 852px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23502i8254A44A6E850A6F/image-dimensions/852x332?v=v2" width="852" height="332" role="button" title="JCANDIAT_2-1674510242190.png" alt="JCANDIAT_2-1674510242190.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JCANDIAT_3-1674510280139.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23503i63FC2CF925320919/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JCANDIAT_3-1674510280139.png" alt="JCANDIAT_3-1674510280139.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jan 2023 16:36:10 GMT</pubDate>
    <dc:creator>JCANDIAT</dc:creator>
    <dc:date>2023-01-25T16:36:10Z</dc:date>
    <item>
      <title>Help with Table Format - JSON</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-Table-Format-JSON/m-p/628047#M107773</link>
      <description>&lt;P&gt;performing the following search:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JCANDIAT_0-1674510125746.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23500i8F3816A6C5B20A51/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JCANDIAT_0-1674510125746.png" alt="JCANDIAT_0-1674510125746.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I get this result. I need to parser this information, building a table excel type. The information is in JSON format, so a UPLOAD in SPLUNK.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JCANDIAT_2-1674510242190.png" style="width: 852px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23502i8254A44A6E850A6F/image-dimensions/852x332?v=v2" width="852" height="332" role="button" title="JCANDIAT_2-1674510242190.png" alt="JCANDIAT_2-1674510242190.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JCANDIAT_3-1674510280139.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23503i63FC2CF925320919/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JCANDIAT_3-1674510280139.png" alt="JCANDIAT_3-1674510280139.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 16:36:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-Table-Format-JSON/m-p/628047#M107773</guid>
      <dc:creator>JCANDIAT</dc:creator>
      <dc:date>2023-01-25T16:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: Table Format - JSON</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-Table-Format-JSON/m-p/628049#M107775</link>
      <description>&lt;P&gt;This might be easier from the _raw JSON events. Please can you share anonymised events in a code block &amp;lt;/&amp;gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 23:12:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-Table-Format-JSON/m-p/628049#M107775</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-01-23T23:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: Table Format - JSON</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-Table-Format-JSON/m-p/628052#M107776</link>
      <description>&lt;P&gt;{"Threat_hunting": {&lt;BR /&gt;"cliente": "paginaejemplo.com.ar",&lt;BR /&gt;"data": {&lt;BR /&gt;"1": {&lt;BR /&gt;"identificador": "551e5ae3-133a-463e-b3db-404f9e33ce1c",&lt;BR /&gt;"name": "ES_139.47.115.rar/passwords.txt",&lt;BR /&gt;"date": "2023-01-11T06:12:26.576428Z",&lt;BR /&gt;"credenciales": {&lt;BR /&gt;"1": {&lt;BR /&gt;"Application": "Chrome (v106.0.5249.91-64, Profile",&lt;BR /&gt;"URL": "&lt;A href="https://www.paginaejemplo.com.ar" target="_blank"&gt;https://www.paginaejemplo.com.ar&lt;/A&gt;",&lt;BR /&gt;"Username": "",&lt;BR /&gt;"Password": "dddddddd"&lt;BR /&gt;},&lt;BR /&gt;"2": {&lt;BR /&gt;"Application": "Chrome (v106.0.5249.91-64, Profile",&lt;BR /&gt;"URL": "&lt;A href="https://www.paginaejemplo.com.ar" target="_blank"&gt;https://www.paginaejemplo.com.ar&lt;/A&gt;",&lt;BR /&gt;"Username": "",&lt;BR /&gt;"Password": "bbbbbb"&lt;BR /&gt;},&lt;BR /&gt;"3": {&lt;BR /&gt;"Application": "Chrome (v106.0.5249.91-64, Profile",&lt;BR /&gt;"URL": "&lt;A href="https://www.paginaejemplo.com.ar" target="_blank"&gt;https://www.paginaejemplo.com.ar&lt;/A&gt;",&lt;BR /&gt;"Username": "",&lt;BR /&gt;"Password": "aaaaaa"&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;},&lt;BR /&gt;"2": {&lt;BR /&gt;"identificador": "b540adda-6f78-40d7-bef4-f3413024fc71",&lt;BR /&gt;"name": "AR[8BB40128FD52DCE2DD16C34FE4DA496E] [2022-11-05T18_37_34.rar/ AR[8BB40128FD52DCE2DD16C34FE4DA496E] [2022-11-05T18_37_34/Passwords.txt",&lt;BR /&gt;"date": "2023-01-14T05:11:44.593095Z",&lt;BR /&gt;"credenciales": {&lt;BR /&gt;"1": {&lt;BR /&gt;"URL": "&lt;A href="https://www.paginaejemplo.com.ar" target="_blank"&gt;https://www.paginaejemplo.com.ar&lt;/A&gt;",&lt;BR /&gt;"Username": "UNKNOWN",&lt;BR /&gt;"Password": "fffffff",&lt;BR /&gt;"Application": "Google_[Chrome]_Profile 1"&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 23:21:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-Table-Format-JSON/m-p/628052#M107776</guid>
      <dc:creator>JCANDIAT</dc:creator>
      <dc:date>2023-01-23T23:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: Table Format - JSON</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-Table-Format-JSON/m-p/628056#M107777</link>
      <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=key "Threat_hunting\.data\.(?&amp;lt;data&amp;gt;\d+)\.credenciales\.(?&amp;lt;credencial&amp;gt;\d+)\.(?&amp;lt;key&amp;gt;\w+)"
| eval {key}=value
| fields data credencial Application Password URL Username
| stats values(*) as * by data credencial&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 24 Jan 2023 00:31:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-Table-Format-JSON/m-p/628056#M107777</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-01-24T00:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Table Format - JSON</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-Table-Format-JSON/m-p/628139#M107805</link>
      <description>&lt;P&gt;Thank you very much!!!&lt;/P&gt;&lt;P&gt;It works!&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 13:31:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-Table-Format-JSON/m-p/628139#M107805</guid>
      <dc:creator>JCANDIAT</dc:creator>
      <dc:date>2023-01-24T13:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Table Format - JSON</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-Table-Format-JSON/m-p/628207#M107819</link>
      <description>&lt;P&gt;Dear,&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can i build this structure, have in mind the identification label?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JCANDIAT_1-1674594086796.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23523iE71109BA859FF173/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JCANDIAT_1-1674594086796.png" alt="JCANDIAT_1-1674594086796.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;grateful for your help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 21:02:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-Table-Format-JSON/m-p/628207#M107819</guid>
      <dc:creator>JCANDIAT</dc:creator>
      <dc:date>2023-01-24T21:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: Table Format - JSON</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-Table-Format-JSON/m-p/628211#M107820</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rex field=key "Threat_hunting\.data\.(?&amp;lt;data&amp;gt;\d+)\.credenciales\.(?&amp;lt;credencial&amp;gt;\d+)\.(?&amp;lt;key&amp;gt;\w+)"
| rex field=key "Threat_hunting\.data\.(?&amp;lt;data&amp;gt;\d+)\.(?&amp;lt;key&amp;gt;identificador|date)"
| eval {key}=value
| fillnull value=0 credencial
| fields data credencial identificador date Password URL Username
| stats values(*) as * by data credencial
| eventstats values(date) as date values(identificador) as identificador by data
| where credencial != 0&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 24 Jan 2023 22:40:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-Table-Format-JSON/m-p/628211#M107820</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-01-24T22:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: Table Format - JSON</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-Table-Format-JSON/m-p/628216#M107821</link>
      <description>&lt;P&gt;thank you very much for your knowledge!&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 23:44:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-Table-Format-JSON/m-p/628216#M107821</guid>
      <dc:creator>JCANDIAT</dc:creator>
      <dc:date>2023-01-24T23:44:44Z</dc:date>
    </item>
  </channel>
</rss>

