<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Convert Splunk results from spl to JSON before 8.2 in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Convert-Splunk-results-from-spl-to-JSON-before-8-2/m-p/565769#M197141</link>
    <description>&lt;P&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238057"&gt;@D0do&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I believe this is what you're looking for:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-to-convert-an-event-INTO-JSON/m-p/288299" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/How-to-convert-an-event-INTO-JSON/m-p/288299&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;S&lt;/P&gt;&lt;P&gt;***If this helped, please accept it as a solution. It helps others to find the solution for similar issues quickly.***&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 Sep 2021 10:27:10 GMT</pubDate>
    <dc:creator>shivanshu1593</dc:creator>
    <dc:date>2021-09-03T10:27:10Z</dc:date>
    <item>
      <title>Convert Splunk results from spl to JSON before 8.2</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-Splunk-results-from-spl-to-JSON-before-8-2/m-p/565763#M197139</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P data-unlink="true"&gt;I'm using an spl query that extracts some values from a lookup and sends them to a web API via POST request (for this i'm using the WebTools &lt;A href="https://splunkbase.splunk.com/app/4146/#/details" target="_blank" rel="noopener"&gt;add-on&lt;/A&gt;).&lt;/P&gt;&lt;P data-unlink="true"&gt;To send data formatted as reported in the api swagger, I'm using the Splunk command "tojson" to convert Spl query results to Json in my test instance.&lt;/P&gt;&lt;P data-unlink="true"&gt;Since the tojson command is really new (props to Splunk for adding this!) and was introduced from 8.2, is there a way to do the same in previous Splunk versions?&lt;/P&gt;&lt;P data-unlink="true"&gt;Splunk Query:&amp;nbsp;&lt;EM&gt;|inputlookup l2d.csv |eventstats values(tp) as id | table id,code | tojson &amp;lt;...curl using raw field from tojson&amp;gt;&lt;/EM&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;Json format expected and produced with tojson command:&amp;nbsp;{"id":["id1","id2"],"code":"00001"}&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;Thank you for the attention, have a nice day,&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 09:48:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-Splunk-results-from-spl-to-JSON-before-8-2/m-p/565763#M197139</guid>
      <dc:creator>D0do</dc:creator>
      <dc:date>2021-09-03T09:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: Convert Splunk results from spl to JSON before 8.2</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-Splunk-results-from-spl-to-JSON-before-8-2/m-p/565769#M197141</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238057"&gt;@D0do&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I believe this is what you're looking for:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-to-convert-an-event-INTO-JSON/m-p/288299" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/How-to-convert-an-event-INTO-JSON/m-p/288299&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;S&lt;/P&gt;&lt;P&gt;***If this helped, please accept it as a solution. It helps others to find the solution for similar issues quickly.***&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 10:27:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-Splunk-results-from-spl-to-JSON-before-8-2/m-p/565769#M197141</guid>
      <dc:creator>shivanshu1593</dc:creator>
      <dc:date>2021-09-03T10:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Convert Splunk results from spl to JSON before 8.2</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-Splunk-results-from-spl-to-JSON-before-8-2/m-p/565770#M197142</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/61125"&gt;@shivanshu1593&lt;/a&gt;, much appreciated&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 10:38:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-Splunk-results-from-spl-to-JSON-before-8-2/m-p/565770#M197142</guid>
      <dc:creator>D0do</dc:creator>
      <dc:date>2021-09-03T10:38:09Z</dc:date>
    </item>
  </channel>
</rss>

