<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Re-arranging Json fields while indexing the data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Re-arranging-Json-fields-while-indexing-the-data/m-p/712204#M117607</link>
    <description>&lt;P&gt;What do you hope to achieve which can't be done in SPL and your dashboard searches?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2025 13:44:19 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2025-02-21T13:44:19Z</dc:date>
    <item>
      <title>Re-arranging Json fields while indexing the data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-arranging-Json-fields-while-indexing-the-data/m-p/712197#M117604</link>
      <description>&lt;P&gt;This is how our normal raw event looks --&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Feb&lt;/SPAN&gt; &lt;SPAN class=""&gt;7&lt;/SPAN&gt; &lt;SPAN class=""&gt;23:59:32&lt;/SPAN&gt; &lt;SPAN class=""&gt;128.160.82.26&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;local0.warning&lt;/SPAN&gt;&lt;SPAN&gt;] &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;132&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;1&lt;/SPAN&gt; &lt;SPAN class=""&gt;2025-02-07T23:59:32.033309Z&lt;/SPAN&gt; &lt;SPAN class=""&gt;AviVantage&lt;/SPAN&gt; &lt;SPAN class=""&gt;v-wasphictst-wdc.hc.cloud.uk.sony-443&lt;/SPAN&gt; &lt;SPAN class=""&gt;NILVALUE&lt;/SPAN&gt; &lt;SPAN class=""&gt;NILVALUE&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; {"&lt;/SPAN&gt;&lt;SPAN class=""&gt;adf&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:true&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;significant&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;udf&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:false&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;virtualservice&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;virtualservice-e52d1117-b508-4a6d-9fb5-f03ca6319af7&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;report_timestamp&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;2025-02-07T23:59:32.033309Z&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;service_engine&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;GB-DRN-AB-Tier2-se-bmqhk&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;vcpu_id&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;log_id&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:89302&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;client_ip&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;112.12.53.70&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;client_src_port&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:37228&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;client_dest_port&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:443&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;client_rtt&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:1&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;request_state&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;AVI_HTTP_REQUEST_STATE_SSL_HANDSHAKING&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;significant_log&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;["&lt;/SPAN&gt;&lt;SPAN class=""&gt;ADF_CLIENT_CONNECTION_CLOSED_BEFORE_REQUEST&lt;/SPAN&gt;&lt;SPAN&gt;"],"&lt;/SPAN&gt;&lt;SPAN class=""&gt;vs_ip&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;128.160.71.101&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;ocsp_status_resp_sent&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:true&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;max_ingress_latency_fe&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;avg_ingress_latency_fe&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;conn_est_time_fe&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:1&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;source_ip&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;128.12.53.70&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;vs_name&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;v-wasphictst-wdc.hc.cloud.uk.sony-443&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;tenant_name&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;admin&lt;/SPAN&gt;&lt;SPAN&gt;"}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So what we have does is removed the non-json part from this by using sedcmd and extracted the json events by giving kv_mode=json in SH. Till here it is good.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Formatted log sample - &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;[-]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;adf&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;true&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;all_request_headers&lt;/SPAN&gt;:&amp;nbsp;{&amp;nbsp;[+]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;all_response_headers&lt;/SPAN&gt;:&amp;nbsp;{ [+]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;avg_ingress_latency_fe&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;cacheable&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;true&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;client_dest_port&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;443&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;client_insights&lt;/SPAN&gt;:&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;client_ip&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;112.11.227.250&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;client_rtt&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;client_src_port&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;34057&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;compression&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;NO_COMPRESSION_CAN_BE_COMPRESSED&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;compression_percentage&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;conn_est_time_fe&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;host&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;wasphictst-wdc.hc.cloud.uk.sony&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;http_version&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;1.1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;jwt_log&lt;/SPAN&gt;:&amp;nbsp;{ [+]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;log_id&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;122364&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;max_ingress_latency_fe&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;method&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;GET&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;report_timestamp&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;2025-02-18T16:30:29.084682Z&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;request_headers&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;577&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;request_id&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;6vT-vgq1-nSjL&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;request_length&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;131&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;request_state&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;AVI_HTTP_REQUEST_STATE_READ_CLIENT_REQ_HDR&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;response_code&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;403&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;response_content_type&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;text/html&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;response_headers&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;12&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;response_length&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;4181&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;response_time_first_byte&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;response_time_last_byte&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;service_engine&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;GB-DRN-AB-Tier2-se-vxeuz&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;significant&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;significant_log&lt;/SPAN&gt;:&amp;nbsp;[ [+]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;]&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;sni_hostname&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;wasphictst-wdc.hc.cloud.uk.sony&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;source_ip&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;128.11.227.250&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;ssl_cipher&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;TLS_AES_256_GCM_SHA384&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;ssl_session_id&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;5032f265bd7d88f768c096bbbf78d4f2&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;ssl_version&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;TLSv1.3&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;tenant_name&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;admin&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;udf&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;false&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;uri_path&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;/cmd&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;user_agent&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;insomnia/2021.5.3&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;vcpu_id&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;virtualservice&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;virtualservice-e52d1117-b508-4a6d-9fb5-f03ca6319af7&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;vs_ip&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;123.160.71.101&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;vs_name&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;v-wasphictst-wdc.hc.cloud.uk.sony-443&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;waf_log&lt;/SPAN&gt;:&amp;nbsp;{ [+]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/SPAN&gt;&lt;BR /&gt;}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We want to re-arrange this fields that is we have some less information strings at the top and more info fields like (waf_log) at the bottom. how to do this re-arranging part? Checked from source end and they can't do anything from their side.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And one more thing, want waf_log to be automatically expanded by default not everytime by clicking + and again + + + in this way. Please help me in these two requirements?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 12:35:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-arranging-Json-fields-while-indexing-the-data/m-p/712197#M117604</guid>
      <dc:creator>Karthikeya</dc:creator>
      <dc:date>2025-02-21T12:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: Re-arranging Json fields while indexing the data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-arranging-Json-fields-while-indexing-the-data/m-p/712204#M117607</link>
      <description>&lt;P&gt;What do you hope to achieve which can't be done in SPL and your dashboard searches?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 13:44:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-arranging-Json-fields-while-indexing-the-data/m-p/712204#M117607</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-02-21T13:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: Re-arranging Json fields while indexing the data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-arranging-Json-fields-while-indexing-the-data/m-p/712208#M117609</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273888"&gt;@Karthikeya&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reason waf_logs is at the bottom is because JSON events are output in alphabetical order when viewed as a JSON formatted event, and it isnt expanded because it is a child to the main event.&lt;/P&gt;&lt;P&gt;These are things which cannot be changed when viewing it in this way, however you could create dashboards perhaps to display the data in a table or something like that if this is preferred?&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider accepting this answer or adding karma this answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 14:09:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-arranging-Json-fields-while-indexing-the-data/m-p/712208#M117609</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-02-21T14:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: Re-arranging Json fields while indexing the data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-arranging-Json-fields-while-indexing-the-data/m-p/712209#M117610</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;We want the log events to be in such a manner which is useful for our app owners.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For suppose in my sample log...&amp;nbsp;&lt;SPAN class=""&gt;avg_ingress_latency_fe:&amp;nbsp;0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;cacheable:&amp;nbsp;true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;client_dest_port:&amp;nbsp;443&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;client_insights:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;These strings which are beginning are not at all useful (but can't be removed) but waf_log which is at the bottom is more important and want this in the beginning.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp; &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;Yes I achieved it by creating dashboard, but even after they click on any dashboard panel, they will be seeing the same less imp strings (the same event format) which is not supposed to be.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 14:13:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-arranging-Json-fields-while-indexing-the-data/m-p/712209#M117610</guid>
      <dc:creator>Karthikeya</dc:creator>
      <dc:date>2025-02-21T14:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: Re-arranging Json fields while indexing the data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-arranging-Json-fields-while-indexing-the-data/m-p/712211#M117612</link>
      <description>&lt;P&gt;I see, sorry - I dont think it is possible to achieve what you are looking for without removing the fields you dont want to see from the source data.&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider accepting this answer or adding karma this answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 14:16:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-arranging-Json-fields-while-indexing-the-data/m-p/712211#M117612</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-02-21T14:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: Re-arranging Json fields while indexing the data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-arranging-Json-fields-while-indexing-the-data/m-p/712212#M117613</link>
      <description>&lt;P&gt;Created 4 panels for waf_logs as below:&lt;/P&gt;&lt;P&gt;Base Search - Index=a sourcetype=xxx:xxxx |fields * |fillnull value = "NULL"&lt;/P&gt;&lt;P&gt;Panel - 1&lt;/P&gt;&lt;P&gt;|search client_ip= "$cli_ip$" uri_query = "$uri_que$" waf_log.rule_logs{}.rule_id="$rule_id$" waf_log.rule_logs{}.rule_name="$rule_name$" waf_log.status="$log_status$" waf_log.rule_logs{}.msg="$log_mess$" |stats count by waf_log.rule_logs{}.rule_group |rename waf_log.rule_logs{}.rule_group as "Rule Group" |sort - count&lt;/P&gt;&lt;P&gt;Panel 2 -&amp;nbsp;&lt;/P&gt;&lt;P&gt;|search client_ip= "$cli_ip$" uri_query = "$uri_que$" waf_log.rule_logs{}.rule_id="$rule_id$" waf_log.rule_logs{}.rule_name="$rule_name$" waf_log.status="$log_status$" waf_log.rule_logs{}.msg="$log_mess$" |stats count by waf_log.rule_logs{}.rule_id&lt;BR /&gt;|rename waf_log.rule_logs{}.rule_id as "Rule ID" |sort - count&lt;/P&gt;&lt;P&gt;Panel 3 -&amp;nbsp;&lt;/P&gt;&lt;P&gt;|search client_ip= "$cli_ip$" uri_query = "$uri_que$" waf_log.rule_logs{}.rule_id="$rule_id$" waf_log.rule_logs{}.rule_name="$rule_name$" waf_log.status="$log_status$" waf_log.rule_logs{}.msg="$log_mess$" |stats count by waf_log.status&lt;BR /&gt;|rename waf_log.status as "Log Status" |sort - count&lt;/P&gt;&lt;P&gt;Panel 4 -&amp;nbsp;&lt;/P&gt;&lt;P&gt;|search client_ip= "$cli_ip$" uri_query = "$uri_que$" waf_log.rule_logs{}.rule_id="$rule_id$" waf_log.rule_logs{}.rule_name="$rule_name$" waf_log.status="$log_status$" waf_log.rule_logs{}.msg="$log_mess$" |stats count by waf_log.rule_logs{}.msg&lt;BR /&gt;|rename waf_log.rule_logs{}.msg as "Log Message" |sort - count&lt;/P&gt;&lt;P&gt;Any suggestions on these dashboard to make it more readable when they click on any of the value?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 14:17:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-arranging-Json-fields-while-indexing-the-data/m-p/712212#M117613</guid>
      <dc:creator>Karthikeya</dc:creator>
      <dc:date>2025-02-21T14:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: Re-arranging Json fields while indexing the data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-arranging-Json-fields-while-indexing-the-data/m-p/712244#M117620</link>
      <description>&lt;P&gt;Create another dashboard or panel which displays the event as you would like it and modify the drilldown on the original panel(s) to link to the new dashboard or make the new panel visible in the current dashboard.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 17:03:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-arranging-Json-fields-while-indexing-the-data/m-p/712244#M117620</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-02-21T17:03:06Z</dc:date>
    </item>
  </channel>
</rss>

