<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk - how to filter json search results in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/510127#M86734</link>
    <description>&lt;P&gt;&lt;SPAN&gt;My search | spath&amp;nbsp;agent{} output=agent&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;| mvexpand agent | spath input=agent | search agentName="ether"&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jul 2020 21:36:29 GMT</pubDate>
    <dc:creator>to4kawa</dc:creator>
    <dc:date>2020-07-20T21:36:29Z</dc:date>
    <item>
      <title>Splunk - how to filter json search results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/510039#M86729</link>
      <description>&lt;P&gt;My splunk search returns one event as below: notice &lt;STRONG&gt;agent&lt;/STRONG&gt;&amp;nbsp;data is in a nested json format.&amp;nbsp; &lt;STRONG&gt;agentName&lt;/STRONG&gt; and &lt;STRONG&gt;agentSwitch&lt;/STRONG&gt; are nested fields within &lt;STRONG&gt;agent&lt;/STRONG&gt;.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="testsplunk.JPG" style="width: 302px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9784i56BE9A77DCEB480A/image-size/large?v=v2&amp;amp;px=999" role="button" title="testsplunk.JPG" alt="testsplunk.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I would like to filter within this result so that the output would only display&amp;nbsp;&lt;/P&gt;&lt;P&gt;agentName = "ether" and agentSwitchName="soul".&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried to filter using spath and table but each time it would return ALL agentNames, how can i correctly filter the output?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My search | spath | table environemnt, agent{}.agentName | search agent{}.agentName="ether"&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 14:01:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/510039#M86729</guid>
      <dc:creator>evanxu</dc:creator>
      <dc:date>2020-07-20T14:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk - how to filter json search results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/510127#M86734</link>
      <description>&lt;P&gt;&lt;SPAN&gt;My search | spath&amp;nbsp;agent{} output=agent&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;| mvexpand agent | spath input=agent | search agentName="ether"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 21:36:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/510127#M86734</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-07-20T21:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk - how to filter json search results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/510333#M86759</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/184221"&gt;@to4kawa&lt;/a&gt;&amp;nbsp;, thank you, i have one more request,&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;my search correctly returns agent ether, however, it also returns &lt;STRONG&gt;all&lt;/STRONG&gt; agent switch names even though I specified agentSwitchName "soul".&amp;nbsp; &amp;nbsp;I think this has to do with agentSwitchName being nested within agent.&amp;nbsp; &amp;nbsp;Could you help ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;mysearch |&amp;nbsp;&amp;nbsp;spath&amp;nbsp;agent{} output=agent |&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;mvexpand agent | spath input=agent&lt;BR /&gt;| search agentName="ether" AND agentSwitchName="soul"&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 02:42:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/510333#M86759</guid>
      <dc:creator>evanxu</dc:creator>
      <dc:date>2020-07-22T02:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk - how to filter json search results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/510388#M86764</link>
      <description>&lt;P&gt;I don't know your log. I can't do that.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 09:38:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/510388#M86764</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-07-22T09:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk - how to filter json search results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/510415#M86766</link>
      <description>&lt;P&gt;The json screenshot is the result of my search, it returns a &lt;STRONG&gt;single&lt;/STRONG&gt; event with nested json.&amp;nbsp; &amp;nbsp;I am attempting to reformat/filter the event output to show only agentName: ether and agentSwitchName: soul, preferably in a tabular format.&amp;nbsp; &lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="testsplunk.JPG" style="width: 302px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9819iFCE767EB30D8729D/image-size/large?v=v2&amp;amp;px=999" role="button" title="testsplunk.JPG" alt="testsplunk.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;mysearch |&amp;nbsp;&amp;nbsp;spath&amp;nbsp;agent{} output=agent |&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;mvexpand agent | spath input=agent&lt;BR /&gt;| search agentName="ether" AND agentSwitchName="soul"&amp;nbsp; | table&amp;nbsp;agentName,&amp;nbsp;agentSwitchName&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;However instead of getting "soul" only, I am getting both "infinity" and "soul", so it looks like&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="current.JPG" style="width: 217px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9821iFC5E0E444F298498/image-size/large?v=v2&amp;amp;px=999" role="button" title="current.JPG" alt="current.JPG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;This is the output I really want:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="target.JPG" style="width: 214px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9820i607EAA5D6CEC5DD5/image-size/large?v=v2&amp;amp;px=999" role="button" title="target.JPG" alt="target.JPG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 12:07:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/510415#M86766</guid>
      <dc:creator>evanxu</dc:creator>
      <dc:date>2020-07-22T12:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk - how to filter json search results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/510448#M86769</link>
      <description>&lt;P&gt;&lt;SPAN&gt;you can do it, I can't do it by only sample pics.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 13:42:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/510448#M86769</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-07-22T13:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk - how to filter json search results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/510478#M86772</link>
      <description>&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Hi,&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Best thing I do in this situation is changing log display format to "Raw" and capture correct left and right boundaries with rex command. (If require max_match option). Right now default json view would be "List" view.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="spitchika_0-1595430181338.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9826iCA6774E356DE5018/image-size/large?v=v2&amp;amp;px=999" role="button" title="spitchika_0-1595430181338.png" alt="spitchika_0-1595430181338.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 15:07:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/510478#M86772</guid>
      <dc:creator>spitchika</dc:creator>
      <dc:date>2020-07-22T15:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk - how to filter json search results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/511028#M86813</link>
      <description>&lt;P&gt;Thank you for the hint.&amp;nbsp; &amp;nbsp; I tried to add the clause below and the data returned correctly.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;| rename data as _raw&lt;BR /&gt;| extract&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 02:07:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/511028#M86813</guid>
      <dc:creator>evanxu</dc:creator>
      <dc:date>2020-07-27T02:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk - how to filter json search results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/511138#M86823</link>
      <description>&lt;LI-CODE lang="markup"&gt;Perfect!! Thank you.&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 27 Jul 2020 14:47:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-how-to-filter-json-search-results/m-p/511138#M86823</guid>
      <dc:creator>spitchika</dc:creator>
      <dc:date>2020-07-27T14:47:31Z</dc:date>
    </item>
  </channel>
</rss>

