<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to extract mutiple value from json in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-mutiple-value-from-json/m-p/604213#M210165</link>
    <description>&lt;P&gt;thanks for your help! the result is "37.0.10.15.judgments{}" and "47.105.153.104.judgments{}", what can I do if I want to stats the two judgments to one field?&lt;/P&gt;</description>
    <pubDate>Sat, 02 Jul 2022 03:10:28 GMT</pubDate>
    <dc:creator>zhenqi</dc:creator>
    <dc:date>2022-07-02T03:10:28Z</dc:date>
    <item>
      <title>How to extract mutiple value from json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-mutiple-value-from-json/m-p/604098#M210139</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I want to extract judgments to a fields from&amp;nbsp;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;37.0.10.15&lt;/SPAN&gt;&lt;SPAN&gt;" and&amp;nbsp;"&lt;SPAN class=""&gt;47.105.153.104&lt;/SPAN&gt;",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Is there any way it can do that?&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;data&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;37.0.10.15&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;severity&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;medium&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;judgments&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;["&lt;/SPAN&gt;&lt;SPAN class=""&gt;Scanner&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;Zombie&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;Spam&lt;/SPAN&gt;&lt;SPAN&gt;"],"&lt;/SPAN&gt;&lt;SPAN class=""&gt;tags_classes&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;[],"&lt;/SPAN&gt;&lt;SPAN class=""&gt;basic&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;carrier&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Delis&lt;/SPAN&gt; &lt;SPAN class=""&gt;LLC&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;location&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;country&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;The&lt;/SPAN&gt; &lt;SPAN class=""&gt;Netherlands&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;province&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Zuid-Holland&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;city&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Brielle&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;lng&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;4.16361&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;lat&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;51.90248&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;country_code&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;NL&lt;/SPAN&gt;&lt;SPAN&gt;"}},"&lt;/SPAN&gt;&lt;SPAN class=""&gt;asn&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{},"&lt;/SPAN&gt;&lt;SPAN class=""&gt;scene&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"","&lt;/SPAN&gt;&lt;SPAN class=""&gt;confidence_level&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;high&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;is_malicious&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:true&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;update_time&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;2022-06-20&lt;/SPAN&gt; &lt;SPAN class=""&gt;13:00:09&lt;/SPAN&gt;&lt;SPAN&gt;"},"&lt;/SPAN&gt;&lt;SPAN class=""&gt;47.105.153.104&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;severity&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;high&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;judgments&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;["&lt;/SPAN&gt;&lt;SPAN class=""&gt;Zombie&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;IDC&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;Exploit&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;Spam&lt;/SPAN&gt;&lt;SPAN&gt;"],"&lt;/SPAN&gt;&lt;SPAN class=""&gt;tags_classes&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;[{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;tags&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;["&lt;/SPAN&gt;&lt;SPAN class=""&gt;Aliyun&lt;/SPAN&gt;&lt;SPAN&gt;"],"&lt;/SPAN&gt;&lt;SPAN class=""&gt;tags_type&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;public_info&lt;/SPAN&gt;&lt;SPAN&gt;"}],"&lt;/SPAN&gt;&lt;SPAN class=""&gt;basic&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;carrier&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Alibaba&lt;/SPAN&gt; &lt;SPAN class=""&gt;Cloud&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;location&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;country&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;China&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;province&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Shandong&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;city&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Qingdao&lt;/SPAN&gt; &lt;SPAN class=""&gt;City&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;lng&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;120.372878&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;lat&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;36.098733&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;country_code&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;CN&lt;/SPAN&gt;&lt;SPAN&gt;"}},"&lt;/SPAN&gt;&lt;SPAN class=""&gt;asn&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;rank&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:2&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;info&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;CNNIC-ALIBABA-CN-NET-AP&lt;/SPAN&gt; &lt;SPAN class=""&gt;Hangzhou&lt;/SPAN&gt; &lt;SPAN class=""&gt;Alibaba&lt;/SPAN&gt; &lt;SPAN class=""&gt;Advertising&lt;/SPAN&gt; &lt;SPAN class=""&gt;Co.&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;Ltd.&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;CN&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;number&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:37963&lt;/SPAN&gt;&lt;SPAN&gt;},"&lt;/SPAN&gt;&lt;SPAN class=""&gt;scene&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Hosting&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;confidence_level&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;high&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;is_malicious&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:true&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;update_time&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;2022-06-27&lt;/SPAN&gt; &lt;SPAN class=""&gt;21:11:32&lt;/SPAN&gt;&lt;SPAN&gt;"}},"&lt;/SPAN&gt;&lt;SPAN class=""&gt;response_code&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;verbose_msg&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;OK&lt;/SPAN&gt;&lt;SPAN&gt;"}&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2022 09:44:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-mutiple-value-from-json/m-p/604098#M210139</guid>
      <dc:creator>zhenqi</dc:creator>
      <dc:date>2022-07-01T09:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract mutiple value from json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-mutiple-value-from-json/m-p/604106#M210144</link>
      <description>&lt;LI-CODE lang="markup"&gt;| spath data
| spath input=data
| fields *.judgments{}&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 01 Jul 2022 11:16:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-mutiple-value-from-json/m-p/604106#M210144</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-07-01T11:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract mutiple value from json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-mutiple-value-from-json/m-p/604213#M210165</link>
      <description>&lt;P&gt;thanks for your help! the result is "37.0.10.15.judgments{}" and "47.105.153.104.judgments{}", what can I do if I want to stats the two judgments to one field?&lt;/P&gt;</description>
      <pubDate>Sat, 02 Jul 2022 03:10:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-mutiple-value-from-json/m-p/604213#M210165</guid>
      <dc:creator>zhenqi</dc:creator>
      <dc:date>2022-07-02T03:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract mutiple value from json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-mutiple-value-from-json/m-p/604220#M210168</link>
      <description>&lt;P&gt;Not sure what you mean by "stats the two judgments to one field, but you can combine them as a single multi-value field like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| spath
| spath input=data
| fields *.judgments{}
| foreach *.judgments{}
    [| eval judgments=if(isnull(judgments),'&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;',mvappend(judgments,'&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'))]&lt;/LI-CODE&gt;</description>
      <pubDate>Sat, 02 Jul 2022 07:20:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-mutiple-value-from-json/m-p/604220#M210168</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-07-02T07:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract mutiple value from json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-mutiple-value-from-json/m-p/604221#M210169</link>
      <description>&lt;P&gt;thanks ! I solved the problem by modifying json format,your answer helps me a lot&lt;/P&gt;</description>
      <pubDate>Sat, 02 Jul 2022 07:24:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-mutiple-value-from-json/m-p/604221#M210169</guid>
      <dc:creator>zhenqi</dc:creator>
      <dc:date>2022-07-02T07:24:26Z</dc:date>
    </item>
  </channel>
</rss>

