<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Additional fields extraction from json data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666687#M111864</link>
    <description>&lt;P&gt;It's not working..&lt;/P&gt;</description>
    <pubDate>Mon, 30 Oct 2023 08:29:01 GMT</pubDate>
    <dc:creator>RSS_STT</dc:creator>
    <dc:date>2023-10-30T08:29:01Z</dc:date>
    <item>
      <title>Additional fields extraction from json data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666649#M111857</link>
      <description>&lt;P&gt;I have field CI extracted from json payload&amp;nbsp;&lt;/P&gt;&lt;P&gt;{&lt;BR /&gt;"Name": "zSeries",&lt;BR /&gt;"Severity":5,&lt;BR /&gt;"Category":"EVENT",&lt;BR /&gt;"SubCategory":"Service issues - Unspecified",&lt;BR /&gt;"TStatus": "OPEN",&lt;BR /&gt;"CI": "V2;Y;Windows;srv048;LogicalDisk;C:",&lt;BR /&gt;"Component": "iphone"&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;Further, i want the CI field value extracted using&amp;nbsp;DELIMS = ";". I have created below props &amp;amp; transforms configuration but not working.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[source::cluster_test]&lt;BR /&gt;REPORT-fields = ci-extraction&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[ci-extraction]&lt;BR /&gt;SOURCE_KEY = CI&lt;BR /&gt;DELIMS = ";"&lt;BR /&gt;FIELDS = CI_V2,CI_1,CI_2,CI_3,CI_4,CI_5&lt;/P&gt;&lt;P&gt;Any help highly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 05:18:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666649#M111857</guid>
      <dc:creator>RSS_STT</dc:creator>
      <dc:date>2023-10-30T05:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Additional fields extraction from json data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666660#M111859</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261968"&gt;@RSS_STT&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I cannot debug your fields extraction without accessing your system, but you could use a regex:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "\"CI\":\s+\"(?&amp;lt;CI_V2&amp;gt;[^;]*);(?&amp;lt;CI_1&amp;gt;[^;]*);(?&amp;lt;CI_2&amp;gt;[^;]*);(?&amp;lt;CI_3&amp;gt;[^;]*);(?&amp;lt;CI_4&amp;gt;[^;]*);(?&amp;lt;CI_5&amp;gt;[^\"]*)"&lt;/LI-CODE&gt;&lt;P&gt;or&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=CI "(?&amp;lt;CI_V2&amp;gt;[^;]*);(?&amp;lt;CI_1&amp;gt;[^;]*);(?&amp;lt;CI_2&amp;gt;[^;]*);(?&amp;lt;CI_3&amp;gt;[^;]*);(?&amp;lt;CI_4&amp;gt;[^;]*);(?&amp;lt;CI_5&amp;gt;[^\"]*)"&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/fndJqR/1" target="_blank"&gt;https://regex101.com/r/fndJqR/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 06:56:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666660#M111859</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-30T06:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Additional fields extraction from json data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666666#M111860</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261968"&gt;@RSS_STT&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can also try adding this in props.conf.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[cluster_test]
EXTRACT-fields = "CI":\s"(?&amp;lt;CI_V2&amp;gt;.*)\;(?&amp;lt;CI_1&amp;gt;.*)\;(?&amp;lt;CI_2&amp;gt;.*)\;(?&amp;lt;CI_3&amp;gt;.*)\;(?&amp;lt;CI_4&amp;gt;.*)\;(?&amp;lt;CI_5&amp;gt;.*)\",&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-10-30 at 12.41.56 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27872i6AF555E1F8A4B877/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-10-30 at 12.41.56 PM.png" alt="Screenshot 2023-10-30 at 12.41.56 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this will help you.&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;If any of my replies help you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 07:12:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666666#M111860</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2023-10-30T07:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: Additional fields extraction from json data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666668#M111861</link>
      <description>&lt;P&gt;CI filed values won't be constant. Sometime it can contain 3 value, sometime 4 or 5 value with &lt;SPAN&gt;semicolon separated&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;But 1st word in CI filed is fix that is V2. How can we handle that with inline rex or with props.&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"CI": "V2;Y;Windows;srv048;LogicalDisk;C:",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"CI": "V2;Y;Linx;srv048",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"CI": "V2;LX;apple;rose;server",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 07:25:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666668#M111861</guid>
      <dc:creator>RSS_STT</dc:creator>
      <dc:date>2023-10-30T07:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: Additional fields extraction from json data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666678#M111863</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261968"&gt;@RSS_STT&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;please try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "\"CI\":\s+\"(?&amp;lt;CI_V2&amp;gt;[^;]*);(?&amp;lt;CI_1&amp;gt;[^;\"]*);(?&amp;lt;CI_2&amp;gt;[^;\"]*);(?&amp;lt;CI_3&amp;gt;[^;\"]*);(?&amp;lt;CI_4&amp;gt;[^;\"]*);(?&amp;lt;CI_5&amp;gt;[^\"]*)"&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 08:02:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666678#M111863</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-30T08:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: Additional fields extraction from json data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666687#M111864</link>
      <description>&lt;P&gt;It's not working..&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 08:29:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666687#M111864</guid>
      <dc:creator>RSS_STT</dc:creator>
      <dc:date>2023-10-30T08:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: Additional fields extraction from json data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666694#M111865</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261968"&gt;@RSS_STT&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;please try this regex:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(?&amp;lt;CI_V2&amp;gt;[^;]*);(?&amp;lt;CI_1&amp;gt;[^;\"]*);(?&amp;lt;CI_2&amp;gt;[^;\"]*);*(?&amp;lt;CI_3&amp;gt;[^;\"]*);*(?&amp;lt;CI_4&amp;gt;[^;\"]*);(?&amp;lt;CI_5&amp;gt;[^\"]*)&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/fndJqR/2" target="_blank"&gt;https://regex101.com/r/fndJqR/2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 08:38:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666694#M111865</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-30T08:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: Additional fields extraction from json data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666851#M111876</link>
      <description>&lt;P&gt;Seems to be working for rest of fields by not for CI_V2.&lt;/P&gt;&lt;P&gt;Creating field value CI_V2=&lt;SPAN&gt;"CI":&lt;/SPAN&gt; &lt;SPAN&gt;"V2 . it should be CI_V2 = V2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2023 05:56:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666851#M111876</guid>
      <dc:creator>RSS_STT</dc:creator>
      <dc:date>2023-10-31T05:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: Additional fields extraction from json data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666852#M111877</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261968"&gt;@RSS_STT&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;sorry! I was focused on the other fields and I forrgot the start of the string, please try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;\"CI\":\s+\"(?&amp;lt;CI_V2&amp;gt;[^;]*);(?&amp;lt;CI_1&amp;gt;[^;\"]*);(?&amp;lt;CI_2&amp;gt;[^;\"]*);*(?&amp;lt;CI_3&amp;gt;[^;\"]*);*(?&amp;lt;CI_4&amp;gt;[^;\"]*);(?&amp;lt;CI_5&amp;gt;[^\"]*)&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/fndJqR/3" target="_blank"&gt;https://regex101.com/r/fndJqR/3&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2023 07:26:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666852#M111877</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-31T07:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: Additional fields extraction from json data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666956#M111886</link>
      <description>&lt;P&gt;CI_5 field extraction is not proper. As of now all last values (C,srv048 &amp;amp; server) are going into CI_5 which is not correct.&lt;/P&gt;&lt;P&gt;"CI": "V2;Y;Windows;srv048;LogicalDisk;C:",&lt;BR /&gt;"CI": "V2;Y;Linx;srv048",&lt;BR /&gt;"CI": "V2;LX;apple;rose;server",&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 06:48:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666956#M111886</guid>
      <dc:creator>RSS_STT</dc:creator>
      <dc:date>2023-11-01T06:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: Additional fields extraction from json data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666977#M111887</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261968"&gt;@RSS_STT&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;sorry I forgor one asterisk, please try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;\"CI\":\s+\"(?&amp;lt;CI_V2&amp;gt;[^;]*);(?&amp;lt;CI_1&amp;gt;[^;\"]*);(?&amp;lt;CI_2&amp;gt;[^;\"]*);*(?&amp;lt;CI_3&amp;gt;[^;\"]*);*(?&amp;lt;CI_4&amp;gt;[^;\"]*);*(?&amp;lt;CI_5&amp;gt;[^;\"]*)&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/fndJqR/4" target="_blank"&gt;https://regex101.com/r/fndJqR/4&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 09:24:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Additional-fields-extraction-from-json-data/m-p/666977#M111887</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-01T09:24:23Z</dc:date>
    </item>
  </channel>
</rss>

