<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: JSON spath mvexpand in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/JSON-spath-mvexpand/m-p/513127#M87012</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129407"&gt;@thambisetty&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please find 1 entry:&lt;/P&gt;&lt;P&gt;{"status": "checked", "os_version": "12.4(3g)", "number_of_device": "1", "advisories": [{"advisory_id": "abcd-1234", "last_updated": "2020-06-08T20:41:10", "cvss_base_score": "6.5", "sg_risk_scoring": "2/4", "first_published": "2020-06-03T16:00:00", "summary": "some comments", "cwe": ["CWE-20"], "cves": ["CVE-1234-5678"]}, {"advisory_id": "cdef-1234", "last_updated": "2020-04-28T17:46:50", "cvss_base_score": "8.8", "sg_risk_scoring": "3/4", "first_published": "2020-01-08T16:00:00", "summary": "some comments", "cwe": ["CWE-352"], "cves": ["CVE-2345-6789"]}, {"advisory_id": "bcde-1234", "last_updated": "2007-01-10T16:00:00", "cvss_base_score": "3.3", "sg_risk_scoring": "1/4", "first_published": "2007-01-10T16:00:00", "summary": "some comments", "cwe": ["CWE-399"], "cves": ["CVE-3456-7897"]}], "os_name": "ios"}&lt;/P&gt;</description>
    <pubDate>Sat, 08 Aug 2020 07:58:47 GMT</pubDate>
    <dc:creator>surekhasplunk</dc:creator>
    <dc:date>2020-08-08T07:58:47Z</dc:date>
    <item>
      <title>JSON spath mvexpand</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/JSON-spath-mvexpand/m-p/513119#M87010</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunk.gts.socgen:8000/en-US/app/TA-openvuln/search?q=search%20index%3Dopenvuln%20%2012.4(3g)&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-24h%40h&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1596858292.787#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;advisories&lt;/SPAN&gt;:&amp;nbsp;[&amp;nbsp;&lt;A href="https://splunk.gts.socgen:8000/en-US/app/TA-openvuln/search?q=search%20index%3Dopenvuln%20%2012.4(3g)&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-24h%40h&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1596858292.787#" target="_blank" rel="noopener"&gt;[+]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;]&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;number_of_device&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;os_name&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;ios&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;os_version&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;1234&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;status&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;checked&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Above is my parent json&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And under advisories i have below json.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="key-name"&gt;advisories&lt;/SPAN&gt;:&amp;nbsp;[&amp;nbsp;&lt;A href="https://splunk.gts.socgen:8000/en-US/app/TA-openvuln/search?q=search%20index%3Dopenvuln%20%2012.4(3g)&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-24h%40h&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1596858292.787#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;{&amp;nbsp;&lt;A href="https://splunk.gts.socgen:8000/en-US/app/TA-openvuln/search?q=search%20index%3Dopenvuln%20%2012.4(3g)&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-24h%40h&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1596858292.787#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;a_id&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;abcd1234&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;cv&lt;/SPAN&gt;:&amp;nbsp;[&amp;nbsp;&lt;A href="https://splunk.gts.socgen:8000/en-US/app/TA-openvuln/search?q=search%20index%3Dopenvuln%20%2012.4(3g)&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-24h%40h&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1596858292.787#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="t string"&gt;random_number&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;]&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;score&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;6.5&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;www&lt;SPAN class="key level-3"&gt;:&amp;nbsp;[&amp;nbsp;&lt;A href="https://splunk.gts.socgen:8000/en-US/app/TA-openvuln/search?q=search%20index%3Dopenvuln%20%2012.4(3g)&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-24h%40h&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1596858292.787#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;www-12&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;]&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;first_published&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;2020-06-03T16:00:00&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;last_updated&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;2020-06-08T20:41:10&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;ab_score&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;2/4&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;summary&lt;/SPAN&gt;:something&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="key level-3"&gt;So here I want to count how many times the ab_score =2/4 and then get the corresponding score=6.5 for each os_version.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="key level-3"&gt;But when i am using spath and mvexpand i am getting 2/4 for all ab_score and all a_id.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="key level-3"&gt;not understanding whats happening. Ideally in the raw data 2/4 is there in only 4 places with 4 ab_score attached to it. But i am receiving more than that and repeated .&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="key level-3"&gt;Please help.&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/127939"&gt;@kamlesh_vaghela&lt;/a&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Aug 2020 04:04:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/JSON-spath-mvexpand/m-p/513119#M87010</guid>
      <dc:creator>surekhasplunk</dc:creator>
      <dc:date>2020-08-08T04:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: JSON spath mvexpand</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/JSON-spath-mvexpand/m-p/513121#M87011</link>
      <description>&lt;P&gt;Can you share raw text of an event?&lt;/P&gt;&lt;P&gt;regex may not match if I write regex based on the event you posted.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Aug 2020 05:43:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/JSON-spath-mvexpand/m-p/513121#M87011</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-08T05:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: JSON spath mvexpand</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/JSON-spath-mvexpand/m-p/513127#M87012</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129407"&gt;@thambisetty&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please find 1 entry:&lt;/P&gt;&lt;P&gt;{"status": "checked", "os_version": "12.4(3g)", "number_of_device": "1", "advisories": [{"advisory_id": "abcd-1234", "last_updated": "2020-06-08T20:41:10", "cvss_base_score": "6.5", "sg_risk_scoring": "2/4", "first_published": "2020-06-03T16:00:00", "summary": "some comments", "cwe": ["CWE-20"], "cves": ["CVE-1234-5678"]}, {"advisory_id": "cdef-1234", "last_updated": "2020-04-28T17:46:50", "cvss_base_score": "8.8", "sg_risk_scoring": "3/4", "first_published": "2020-01-08T16:00:00", "summary": "some comments", "cwe": ["CWE-352"], "cves": ["CVE-2345-6789"]}, {"advisory_id": "bcde-1234", "last_updated": "2007-01-10T16:00:00", "cvss_base_score": "3.3", "sg_risk_scoring": "1/4", "first_published": "2007-01-10T16:00:00", "summary": "some comments", "cwe": ["CWE-399"], "cves": ["CVE-3456-7897"]}], "os_name": "ios"}&lt;/P&gt;</description>
      <pubDate>Sat, 08 Aug 2020 07:58:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/JSON-spath-mvexpand/m-p/513127#M87012</guid>
      <dc:creator>surekhasplunk</dc:creator>
      <dc:date>2020-08-08T07:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: JSON spath mvexpand</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/JSON-spath-mvexpand/m-p/513129#M87014</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=_internal | head 1 | fields _raw _time | eval _raw="{\"status\": \"checked\", \"os_version\": \"12.4(3g)\", \"number_of_device\": \"1\", \"advisories\": [{\"advisory_id\": \"abcd-1234\", \"last_updated\": \"2020-06-08T20:41:10\", \"cvss_base_score\": \"6.5\", \"sg_risk_scoring\": \"2/4\", \"first_published\": \"2020-06-03T16:00:00\", \"summary\": \"some comments\", \"cwe\": [\"CWE-20\"], \"cves\": [\"CVE-1234-5678\"]}, {\"advisory_id\": \"cdef-1234\", \"last_updated\": \"2020-04-28T17:46:50\", \"cvss_base_score\": \"8.8\", \"sg_risk_scoring\": \"3/4\", \"first_published\": \"2020-01-08T16:00:00\", \"summary\": \"some comments\", \"cwe\": [\"CWE-352\"], \"cves\": [\"CVE-2345-6789\"]}, {\"advisory_id\": \"bcde-1234\", \"last_updated\": \"2007-01-10T16:00:00\", \"cvss_base_score\": \"3.3\", \"sg_risk_scoring\": \"1/4\", \"first_published\": \"2007-01-10T16:00:00\", \"summary\": \"some comments\", \"cwe\": [\"CWE-399\"], \"cves\": [\"CVE-3456-7897\"]}], \"os_name\": \"ios\"}"
| spath advisories{} output=advisories
| mvexpand advisories
| spath 
| spath input=advisories
| fields - advisories*
| table *
| fields - _*&lt;/LI-CODE&gt;&lt;P&gt;There is not&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;ab_score, &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;what are you going to ask?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Aug 2020 09:02:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/JSON-spath-mvexpand/m-p/513129#M87014</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-08-08T09:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: JSON spath mvexpand</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/JSON-spath-mvexpand/m-p/513175#M87025</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/184221"&gt;@to4kawa&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot ... it works there is no&amp;nbsp;&lt;STRONG&gt;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;ab_score&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;as it was a mocked data.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The only problem is the os_version and os_name&amp;nbsp; value appears twice&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="surekhasplunk_0-1596939325603.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10136i59FCEC6F478A9D79/image-size/medium?v=v2&amp;amp;px=400" role="button" title="surekhasplunk_0-1596939325603.png" alt="surekhasplunk_0-1596939325603.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Aug 2020 02:16:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/JSON-spath-mvexpand/m-p/513175#M87025</guid>
      <dc:creator>surekhasplunk</dc:creator>
      <dc:date>2020-08-09T02:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: JSON spath mvexpand</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/JSON-spath-mvexpand/m-p/513179#M87026</link>
      <description>&lt;P&gt;your log have &lt;STRONG&gt;one&amp;nbsp;&lt;/STRONG&gt;os_version and os_name.&lt;BR /&gt;my query does not duplicate the field values.&lt;BR /&gt;your props.conf setting is wrong. please contact your splunk admin.&lt;BR /&gt;&lt;BR /&gt;workaround:&lt;BR /&gt;&lt;BR /&gt;...&lt;BR /&gt;| eval os_version=mvdedup(os_version) , os_name=mvdedup(os_name)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Aug 2020 02:44:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/JSON-spath-mvexpand/m-p/513179#M87026</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-08-09T02:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: JSON spath mvexpand</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/JSON-spath-mvexpand/m-p/561598#M100054</link>
      <description>&lt;P&gt;Here's a variation on this answer I came up with that might help others.&amp;nbsp; The variation is it uses regex to match each object in _raw in order to produce the multi-value field "rows" on which to perform the mvexpand.&lt;/P&gt;&lt;P&gt;| rex max_match=0 field=_raw "(?&amp;lt;rows&amp;gt;\{[^\}]+\})"&lt;BR /&gt;| table rows&lt;BR /&gt;| mvexpand rows&lt;BR /&gt;| spath input=rows&lt;BR /&gt;| fields - rows&lt;/P&gt;</description>
      <pubDate>Sat, 31 Jul 2021 15:58:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/JSON-spath-mvexpand/m-p/561598#M100054</guid>
      <dc:creator>wryanthomas</dc:creator>
      <dc:date>2021-07-31T15:58:13Z</dc:date>
    </item>
  </channel>
</rss>

