<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to extract fields from JSON ? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-fields-from-JSON/m-p/462571#M79819</link>
    <description>&lt;P&gt;You can get data by using Spath command . &lt;BR /&gt;
Go through the link below to have more visibility .&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.3/SearchReference/spath"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.3/SearchReference/spath&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 17 Oct 2019 15:14:25 GMT</pubDate>
    <dc:creator>Anantha123</dc:creator>
    <dc:date>2019-10-17T15:14:25Z</dc:date>
    <item>
      <title>How to extract fields from JSON ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-fields-from-JSON/m-p/462570#M79818</link>
      <description>&lt;P&gt;Hi team,&lt;BR /&gt;
I have the below my data format in splunk as EVENT, i am unable to extract data field wise. New to Splunk, Can any one support how to extract this.&lt;/P&gt;

&lt;P&gt;{ [-]&lt;BR /&gt;
   log: 2019-10-15 11:56:47.066     INFO  pappy-command-service:ppe [ankitvinay,baff9b4ace879603,baff9b4ace879603] 23 --- [single-1] c.t.a.p.i.m.c.CommandPublisherImpl       : MSG=publishing to kafka, command=CreateApprovePromotion, step=publish, commandStatusId=a570668b-eaa9-44ed-ac90-ac1de811e14a, promotionId=null, status=success&lt;/P&gt;

&lt;P&gt;stream: stdout&lt;BR /&gt;
   time: 2019-10-15T11:56:47.0664926Z&lt;BR /&gt;
}&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 08:43:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-fields-from-JSON/m-p/462570#M79818</guid>
      <dc:creator>kvnvkumar</dc:creator>
      <dc:date>2019-10-17T08:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract fields from JSON ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-fields-from-JSON/m-p/462571#M79819</link>
      <description>&lt;P&gt;You can get data by using Spath command . &lt;BR /&gt;
Go through the link below to have more visibility .&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.3/SearchReference/spath"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.3/SearchReference/spath&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 15:14:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-fields-from-JSON/m-p/462571#M79819</guid>
      <dc:creator>Anantha123</dc:creator>
      <dc:date>2019-10-17T15:14:25Z</dc:date>
    </item>
  </channel>
</rss>

