<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to filter initial data from a file and process it as a JSON file? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-initial-data-from-a-file-and-process-it-as-a-JSON/m-p/282118#M53926</link>
    <description>&lt;P&gt;HI&lt;/P&gt;

&lt;P&gt;I am reading an input from a TCP input that is coming as below. However, each event is having a set of data prepended which is causing the spath command to fail.&lt;BR /&gt;
I wan to filter out   &lt;CODE&gt;"&amp;lt;01&amp;gt;- hostname  "&lt;/CODE&gt; and provide the remaining part as input for spath command.&lt;BR /&gt;
I need help in getting a regular expression to do it.&lt;/P&gt;

&lt;P&gt;The sample input:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;01&amp;gt;- hostname {"name":"DefaultProfile","version":"1.0","isonjkpFormat":"yyyy-MM-dd'T'HH:mm:ss.SSSZ","type":"Event","category":"RT_FLOW_SESSION_CREATE_LS","protocolID":"6","sev":"1","src":"192.168.1.10","dst":"192.168.1.110","srcPort":"25253","dstPort":"80","ujnhbgtrf":"1","credibility":"1","startnjkpEaqer":"1455617975494","startnjkpISO":"2014-01-19T01:29:30.494-03:00","hnbjkiunjkpEaqer":"1455617975494","hnbjkiunjkpISO":"2014-01-19T04:19:35.494-06:00","mkiophirhbYH":"12abc22z-b812-22h7-234f-551016123jal","devnjkpEaqer":"1455639575000","iopHuimeNJI":"2014-01-19T10:19:35.000-06:00","qweLjctNAT":"192.168.1.210","pinBistYHG":"192.168.1.110","srcGyhNBHAsdn":"1","dstGyhNBHAsdn":"1","qweLjctNATPort":"-1234","pinBistYHGPort":"80","hasIdentity":"false","njukoan":"&amp;lt;01&amp;gt;2 2014-01-19T10:17:45.679Z abcd-efg2-9876z WT_FLOW - WT_FLOW_MJHGTYH_CREATE_BS [helps@2222.2.2.2.2.22 localis-compute-zxcv=\"ABC1\" lokmnb-qazwsxe=\"192.168.1.10\" gtfvbj-qwer=\"25253\" qwertyujhnq-address=\"192.168.1.110\" qwertyujhnq-port=\"80\" compute-zxcv=\"kudoi-http\" bat-mnbvcx-address=\"192.168.1.210\" bat-mnbvcx-port=\"78781\" bat-qwertyujhnq-address=\"192.168.1.110\" batqwertyujhnq-port=\"80\" abc-lkjhgfd-name=\"VX-TYU9-TYU-OPT-2\" pkt-lkjhgfd-name=\"None\" protocol-id=\"9\" asdfgh-name=\"JV-X-P786-QWER-BHV\" source-NMLP-name=\"Z-B768-QWER\" qwertyujhnq-NMLP-name=\"M-B890-POIU\" session-id-32=\"098765432\" username=\"N/A\" roles=\"N/A\" MLKIOP-MNJYHGTS-ASDRNJUPJ=\"NJKI3.9876\" application=\"UNKNOWN\" MKUNJI-application=\"UNKNOWN\" mnbhyujgt=\"UNKNOWN\"]","bgasbnJuh":"1","mnbIPOUN":"other","absIPPOL":"other","basghlothp":"false","muqaloID":"9","qwmnpName":"VV_MJOK_SESSION_AWBHNJ_PK","qwaszxmnlkpotyfh":"Session Nhjuyt","wrtyJhyblascvfght":"Access","eventDescription":"A nyhbgtfr basftio bhg inmuytr.","azcvftghbvgt":"acb","qweTgvfrt":"minj-bag6-7856ab-Hnqasui","abcPecpokk":"och-00-145-987.Net_11_4_5_6","mnbJhbpoiu":"other","oijDgfhbnIjkm":"Poijhgb PKM Mnbgftr Asdervhj Thbgfra","nhjRkyhcfBhytf":"MKI-PLO-ASW","thuHyrtfcQhbnjuytfv":"192.168.1.11"}
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 16 Feb 2016 11:46:33 GMT</pubDate>
    <dc:creator>bkumarm</dc:creator>
    <dc:date>2016-02-16T11:46:33Z</dc:date>
    <item>
      <title>How to filter initial data from a file and process it as a JSON file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-initial-data-from-a-file-and-process-it-as-a-JSON/m-p/282118#M53926</link>
      <description>&lt;P&gt;HI&lt;/P&gt;

&lt;P&gt;I am reading an input from a TCP input that is coming as below. However, each event is having a set of data prepended which is causing the spath command to fail.&lt;BR /&gt;
I wan to filter out   &lt;CODE&gt;"&amp;lt;01&amp;gt;- hostname  "&lt;/CODE&gt; and provide the remaining part as input for spath command.&lt;BR /&gt;
I need help in getting a regular expression to do it.&lt;/P&gt;

&lt;P&gt;The sample input:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;01&amp;gt;- hostname {"name":"DefaultProfile","version":"1.0","isonjkpFormat":"yyyy-MM-dd'T'HH:mm:ss.SSSZ","type":"Event","category":"RT_FLOW_SESSION_CREATE_LS","protocolID":"6","sev":"1","src":"192.168.1.10","dst":"192.168.1.110","srcPort":"25253","dstPort":"80","ujnhbgtrf":"1","credibility":"1","startnjkpEaqer":"1455617975494","startnjkpISO":"2014-01-19T01:29:30.494-03:00","hnbjkiunjkpEaqer":"1455617975494","hnbjkiunjkpISO":"2014-01-19T04:19:35.494-06:00","mkiophirhbYH":"12abc22z-b812-22h7-234f-551016123jal","devnjkpEaqer":"1455639575000","iopHuimeNJI":"2014-01-19T10:19:35.000-06:00","qweLjctNAT":"192.168.1.210","pinBistYHG":"192.168.1.110","srcGyhNBHAsdn":"1","dstGyhNBHAsdn":"1","qweLjctNATPort":"-1234","pinBistYHGPort":"80","hasIdentity":"false","njukoan":"&amp;lt;01&amp;gt;2 2014-01-19T10:17:45.679Z abcd-efg2-9876z WT_FLOW - WT_FLOW_MJHGTYH_CREATE_BS [helps@2222.2.2.2.2.22 localis-compute-zxcv=\"ABC1\" lokmnb-qazwsxe=\"192.168.1.10\" gtfvbj-qwer=\"25253\" qwertyujhnq-address=\"192.168.1.110\" qwertyujhnq-port=\"80\" compute-zxcv=\"kudoi-http\" bat-mnbvcx-address=\"192.168.1.210\" bat-mnbvcx-port=\"78781\" bat-qwertyujhnq-address=\"192.168.1.110\" batqwertyujhnq-port=\"80\" abc-lkjhgfd-name=\"VX-TYU9-TYU-OPT-2\" pkt-lkjhgfd-name=\"None\" protocol-id=\"9\" asdfgh-name=\"JV-X-P786-QWER-BHV\" source-NMLP-name=\"Z-B768-QWER\" qwertyujhnq-NMLP-name=\"M-B890-POIU\" session-id-32=\"098765432\" username=\"N/A\" roles=\"N/A\" MLKIOP-MNJYHGTS-ASDRNJUPJ=\"NJKI3.9876\" application=\"UNKNOWN\" MKUNJI-application=\"UNKNOWN\" mnbhyujgt=\"UNKNOWN\"]","bgasbnJuh":"1","mnbIPOUN":"other","absIPPOL":"other","basghlothp":"false","muqaloID":"9","qwmnpName":"VV_MJOK_SESSION_AWBHNJ_PK","qwaszxmnlkpotyfh":"Session Nhjuyt","wrtyJhyblascvfght":"Access","eventDescription":"A nyhbgtfr basftio bhg inmuytr.","azcvftghbvgt":"acb","qweTgvfrt":"minj-bag6-7856ab-Hnqasui","abcPecpokk":"och-00-145-987.Net_11_4_5_6","mnbJhbpoiu":"other","oijDgfhbnIjkm":"Poijhgb PKM Mnbgftr Asdervhj Thbgfra","nhjRkyhcfBhytf":"MKI-PLO-ASW","thuHyrtfcQhbnjuytfv":"192.168.1.11"}
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 16 Feb 2016 11:46:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-initial-data-from-a-file-and-process-it-as-a-JSON/m-p/282118#M53926</guid>
      <dc:creator>bkumarm</dc:creator>
      <dc:date>2016-02-16T11:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter initial data from a file and process it as a JSON file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-initial-data-from-a-file-and-process-it-as-a-JSON/m-p/282119#M53927</link>
      <description>&lt;P&gt;You can use following props.conf configuration in your Indexer/Heavy Forwarder, to remove that prefix at index time&lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[YourSourceType]
...other configurations...
SEDCMD-removeprefix = s/^([^\{]+)(\{.*)/2/g
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;To do this in your search in-line, try something like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your base search | rex mode=sed "s/^([^\{]+)(\{.*)/2/g" | spath
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 16 Feb 2016 18:03:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-initial-data-from-a-file-and-process-it-as-a-JSON/m-p/282119#M53927</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-02-16T18:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter initial data from a file and process it as a JSON file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-initial-data-from-a-file-and-process-it-as-a-JSON/m-p/282120#M53928</link>
      <description>&lt;P&gt;The final Query that solved my requirement is  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;base search | rex field=_raw mode=sed "s/\&amp;lt;\d+\&amp;gt;\-[^\{]+//g" 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;this Query, even without spath command provides afield value exactly the way we need for analytics.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2016 07:05:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-initial-data-from-a-file-and-process-it-as-a-JSON/m-p/282120#M53928</guid>
      <dc:creator>bkumarm</dc:creator>
      <dc:date>2016-02-17T07:05:42Z</dc:date>
    </item>
  </channel>
</rss>

