<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: extracting nested json in Feedback</title>
    <link>https://community.splunk.com/t5/Feedback/extracting-nested-json/m-p/686611#M324</link>
    <description>&lt;P&gt;you have to search and index the json by branch and nodes.&amp;nbsp; If you need the SPL, let me know.&lt;/P&gt;</description>
    <pubDate>Mon, 06 May 2024 17:59:11 GMT</pubDate>
    <dc:creator>youngsuh</dc:creator>
    <dc:date>2024-05-06T17:59:11Z</dc:date>
    <item>
      <title>extracting nested json</title>
      <link>https://community.splunk.com/t5/Feedback/extracting-nested-json/m-p/686591#M322</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MichaelBs_1-1715008039869.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30701i94A964EBF2C951DD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MichaelBs_1-1715008039869.png" alt="MichaelBs_1-1715008039869.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MichaelBs_2-1715008356513.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30706i325DC18807070B67/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MichaelBs_2-1715008356513.png" alt="MichaelBs_2-1715008356513.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;I am trying to extract the path as a field to do a lookup with it. I've tried but it doesn't work. I need help extracting that path. There are other paths in the data but need that particular path&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 15:15:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Feedback/extracting-nested-json/m-p/686591#M322</guid>
      <dc:creator>MichaelBs</dc:creator>
      <dc:date>2024-05-06T15:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: extracting nested json</title>
      <link>https://community.splunk.com/t5/Feedback/extracting-nested-json/m-p/686605#M323</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 16:57:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Feedback/extracting-nested-json/m-p/686605#M323</guid>
      <dc:creator>MichaelBs</dc:creator>
      <dc:date>2024-05-06T16:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: extracting nested json</title>
      <link>https://community.splunk.com/t5/Feedback/extracting-nested-json/m-p/686611#M324</link>
      <description>&lt;P&gt;you have to search and index the json by branch and nodes.&amp;nbsp; If you need the SPL, let me know.&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 17:59:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Feedback/extracting-nested-json/m-p/686611#M324</guid>
      <dc:creator>youngsuh</dc:creator>
      <dc:date>2024-05-06T17:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: extracting nested json</title>
      <link>https://community.splunk.com/t5/Feedback/extracting-nested-json/m-p/686619#M326</link>
      <description>&lt;P&gt;Is your data being interpreted by Splunk as JSON? Try expanding the event fields and seeing if it automatically extracts the json fields. If not, you'll have to change the indexing of the event so it is read as a JSON object. Then you can use SPATH or the auto-extracted fields to get the desired values.&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 19:40:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Feedback/extracting-nested-json/m-p/686619#M326</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-05-06T19:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: extracting nested json</title>
      <link>https://community.splunk.com/t5/Feedback/extracting-nested-json/m-p/686669#M327</link>
      <description>&lt;P&gt;I need the SPL&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 11:05:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Feedback/extracting-nested-json/m-p/686669#M327</guid>
      <dc:creator>MichaelBs</dc:creator>
      <dc:date>2024-05-07T11:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: extracting nested json</title>
      <link>https://community.splunk.com/t5/Feedback/extracting-nested-json/m-p/686670#M328</link>
      <description>&lt;P&gt;Spath didn't give the right fields&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 11:24:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Feedback/extracting-nested-json/m-p/686670#M328</guid>
      <dc:creator>MichaelBs</dc:creator>
      <dc:date>2024-05-07T11:24:33Z</dc:date>
    </item>
  </channel>
</rss>

