<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk json dymanic field extraction in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-json-dymanic-field-extraction/m-p/614728#M213648</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248955"&gt;@Sanjana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;YOUR_SEARCH
| spath content.kIndexKey_EventMessage{1}.check-ins 
| spath input=content.kIndexKey_EventMessage{1}.check-ins 
| spath output=period_start path=content.kIndexKey_EventMessage{1}.period.start 
| eval period_start = strptime('period_start', "%F")
| foreach *.avail 
    [ eval suffix = mvappend(suffix, "&amp;lt;&amp;lt;MATCHSTR&amp;gt;&amp;gt;")] 
| mvexpand suffix
| eval datevalue = period_start + 86400 * suffix
| fields datevalue
| fieldformat datevalue = strftime(datevalue, "%F")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this will help you.&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;If any of my replies help you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;</description>
    <pubDate>Tue, 27 Sep 2022 10:17:24 GMT</pubDate>
    <dc:creator>kamlesh_vaghela</dc:creator>
    <dc:date>2022-09-27T10:17:24Z</dc:date>
    <item>
      <title>Help with Splunk json dymanic field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-json-dymanic-field-extraction/m-p/614661#M213615</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;
&lt;P&gt;I am trying to extract dynamic field from json .&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;{"&lt;SPAN class=""&gt;period&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;{"&lt;SPAN class=""&gt;start&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;"&lt;SPAN class=""&gt;2023-04-17&lt;/SPAN&gt;","&lt;SPAN class=""&gt;end&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;"&lt;SPAN class=""&gt;2023-05-14&lt;/SPAN&gt;"},"&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;check-ins&lt;/SPAN&gt;&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;{"203":{"avail":5,"price":5},"204":{"avail":5,"price":5},"205":{"avail":5,"price":5},"206":{"avail":5,"price":5},"207":{"avail":5,"price":5},"208":{"avail":5,"price":5},"209":{"avail":5,"price":5},"210":{"avail":5,"price":5},"211":{"avail":5,"price":5},"212":{"avail":5,"price":5},"213":{"avail":5,"price":5},"214":{"avail":5,"price":5},"215":{"avail":5,"price":5},"216":{"avail":5,"price":5},"217":{"avail":5,"price":5},"218":{"avail":5,"price":5},"219":{"avail":19,"price":5},"220":{"avail":19,"price":5},"221":{"avail":19,"price":5},"222":{"avail":19,"price":5},"223":{"avail":19,"price":5},"224":{"avail":19,"price":5},"225":{"avail":19,"price":5},"226":{"avail":19,"price":5},"227":{"avail":19,"price":5},"228":{"avail":19,"price":5},"229":{"avail":20,"price":5},"230":{"avail":20,"price":5}}}&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I need to extract 203,204,205.........till 230 as per data mentioned above then each extracted value will be added in period.start field . At the end I need that&lt;STRONG&gt; date value&lt;/STRONG&gt; after addition&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in advance&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 14:09:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-json-dymanic-field-extraction/m-p/614661#M213615</guid>
      <dc:creator>Sanjana</dc:creator>
      <dc:date>2022-09-27T14:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk json dymanic field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-json-dymanic-field-extraction/m-p/614671#M213620</link>
      <description>&lt;P&gt;This is very much like&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Splunk-Search/How-to-convert-check-ins-index-into-date-then-calculate-desync/m-p/614663/highlight/false#M213616" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Splunk-Search/How-to-convert-check-ins-index-into-date-then-calculate-desync/m-p/614663/highlight/false#M213616&lt;/A&gt;. &amp;nbsp;You can use the same strategy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval period_start = strptime('period.start', "%F")
| foreach check-ins.*.avail
    [eval suffix = mvappend(suffix, "&amp;lt;&amp;lt;MATCHSTR&amp;gt;&amp;gt;")]
| mvexpand suffix
| eval datevalue = period_start + 86400 * suffix
| fields datevalue
| fieldformat datevalue = strftime(datevalue, "%F")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using your sample data, you get&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;datevalue&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-05&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-06&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-07&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-09&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-10&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-11&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-12&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-13&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-14&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-15&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-16&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-17&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-18&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-19&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-20&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-21&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-22&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-23&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-24&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-25&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-26&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-27&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-28&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-29&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-11-30&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-01&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2023-12-02&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Here, I assume you want to display in calendar format, hence fieldformat. &amp;nbsp;If you want the date value to be numeric, just omit that. (The advantage of fieldformat is that the field itself is still in numeric.)&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 05:50:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-json-dymanic-field-extraction/m-p/614671#M213620</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-09-27T05:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk json dymanic field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-json-dymanic-field-extraction/m-p/614717#M213642</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I tried above response.but no luck. I am giving you exact scenario which I m trying to work.&lt;/P&gt;&lt;P&gt;This is my actual json structure of splunk data.&lt;BR /&gt;&lt;BR /&gt;"content":&lt;BR /&gt;{"kIndexKey_EventMessage":&lt;BR /&gt;{&lt;BR /&gt;"period":{"start":"2022-10-03","end":"2022-10-19"},&lt;BR /&gt;"check-ins":{&lt;BR /&gt;"12":{"avail":13,"price":0},&lt;BR /&gt;"13":{"avail":13,"price":0},&lt;BR /&gt;"14":{"avail":13,"price":0},&lt;BR /&gt;"15":{"avail":13,"price":0},&lt;BR /&gt;"16":{"avail":13,"price":0},&lt;BR /&gt;"17":{"avail":13,"price":0},&lt;BR /&gt;"18":{"avail":13,"price":0},&lt;BR /&gt;"19":{"avail":13,"price":0},&lt;BR /&gt;"20":{"avail":13,"price":0},&lt;BR /&gt;"21":{"avail":13,"price":0},&lt;BR /&gt;"22":{"avail":13,"price":0},&lt;BR /&gt;"23":{"avail":13,"price":0},&lt;BR /&gt;"24":{"avail":13,"price":0},&lt;BR /&gt;"25":{"avail":13,"price":0},&lt;BR /&gt;"26":{"avail":13,"price":0},&lt;BR /&gt;"27":{"avail":13,"price":0},&lt;BR /&gt;"28":{"avail":13,"price":0}&lt;BR /&gt;}&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;My search is something like below:&lt;/P&gt;&lt;P&gt;index="index1"&lt;BR /&gt;| fields _raw&lt;BR /&gt;| spath content.kIndexKey_EventMessage{1}.check-ins&lt;BR /&gt;| spath input=content.kIndexKey_EventMessage{1}.check-ins&lt;BR /&gt;|spath output=period_start path=content.kIndexKey_EventMessage{1}.period.start&lt;/P&gt;&lt;P&gt;| eval period_start = strptime('period.start', "%F")&lt;BR /&gt;| foreach check-ins.*.avail&lt;BR /&gt;[eval suffix = mvappend(suffix, "&amp;lt;&amp;lt;MATCHSTR&amp;gt;&amp;gt;")]&lt;BR /&gt;| mvexpand suffix&lt;BR /&gt;| eval datevalue = period_start + 86400 * suffix&lt;BR /&gt;| fields datevalue&lt;BR /&gt;| fieldformat datevalue = strftime(datevalue, "%F")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After executing this -&amp;gt;Getting below erro without any data as you shown&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Field 'suffix' does not exist in the data.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Could you please help me where I m getting wrong in this query&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 09:46:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-json-dymanic-field-extraction/m-p/614717#M213642</guid>
      <dc:creator>Sanjana</dc:creator>
      <dc:date>2022-09-27T09:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk json dymanic field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-json-dymanic-field-extraction/m-p/614728#M213648</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248955"&gt;@Sanjana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;YOUR_SEARCH
| spath content.kIndexKey_EventMessage{1}.check-ins 
| spath input=content.kIndexKey_EventMessage{1}.check-ins 
| spath output=period_start path=content.kIndexKey_EventMessage{1}.period.start 
| eval period_start = strptime('period_start', "%F")
| foreach *.avail 
    [ eval suffix = mvappend(suffix, "&amp;lt;&amp;lt;MATCHSTR&amp;gt;&amp;gt;")] 
| mvexpand suffix
| eval datevalue = period_start + 86400 * suffix
| fields datevalue
| fieldformat datevalue = strftime(datevalue, "%F")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this will help you.&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;If any of my replies help you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 10:17:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-json-dymanic-field-extraction/m-p/614728#M213648</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2022-09-27T10:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk json dymanic field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-json-dymanic-field-extraction/m-p/614767#M213670</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/127939"&gt;@kamlesh_vaghela&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the response. It worked fine.&lt;/P&gt;&lt;P&gt;Sorry to bug you again. I have two queries running separate fine.&lt;/P&gt;&lt;P&gt;1. Query&lt;/P&gt;&lt;P&gt;MY_SEARCH&lt;/P&gt;&lt;P&gt;| spath content.kIndexKey_EventMessage{1}.check-ins&lt;BR /&gt;| spath input=content.kIndexKey_EventMessage{1}.check-ins&lt;BR /&gt;| spath output=period_start path=content.kIndexKey_EventMessage{1}.period.start&lt;BR /&gt;| eval period_start = strptime('period_start', "%F")&lt;BR /&gt;| foreach *.avail&lt;BR /&gt;[ eval suffix = mvappend(suffix, "&amp;lt;&amp;lt;MATCHSTR&amp;gt;&amp;gt;")]&lt;BR /&gt;| mvexpand suffix&lt;BR /&gt;| eval datevalue = period_start + 86400 * suffix&lt;BR /&gt;| fields datevalue&lt;BR /&gt;| fieldformat datevalue = strftime(datevalue, "%F")&lt;BR /&gt;|table datevalue&lt;/P&gt;&lt;P&gt;Output&amp;nbsp;&lt;/P&gt;&lt;P&gt;datevalue&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;2022-09-27&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-09-28&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-09-29&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-09-30&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2.Query:&lt;/P&gt;&lt;P&gt;My_Search&lt;/P&gt;&lt;P&gt;| fields _raw&lt;BR /&gt;|spath output=chain path=content.kIndexKey_EventMessage{1}.chain&lt;BR /&gt;|spath output=start path=content.kIndexKey_EventMessage{1}.period.start&lt;BR /&gt;| where like(chain, "IHG%")&lt;BR /&gt;| spath content.kIndexKey_EventMessage{1}.check-ins&lt;BR /&gt;| spath input=content.kIndexKey_EventMessage{1}.check-ins&lt;BR /&gt;| foreach *.check-ins&lt;BR /&gt;[| eval "&amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;"='&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'+'start']&lt;BR /&gt;| foreach *.avail&lt;BR /&gt;[| eval "&amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;"='&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;']&lt;BR /&gt;| foreach *.price&lt;BR /&gt;[| eval "&amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;"='&amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;'+'&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;']&lt;BR /&gt;| dedup _raw,_time&lt;BR /&gt;| fields - *.avail *.price check_ins check-ins _time&lt;BR /&gt;| untable _raw check_ins nb_desync&lt;BR /&gt;| search nb_desync &amp;gt; 0&lt;BR /&gt;| stats sum(nb_desync) as nb_desync by check_ins | sort -nb_desync&lt;BR /&gt;|join type=left&lt;BR /&gt;[search index="int-acrs-cde_appevent-shared"&lt;BR /&gt;|spath output=chain path=content.kIndexKey_EventMessage{1}.chain&lt;BR /&gt;| where like(chain, "IHG")&lt;BR /&gt;|spath output=nb_avail_desync path=content.kIndexKey_EventMessage{1}.total.avail&lt;BR /&gt;|spath output=nb_price_desync path=content.kIndexKey_EventMessage{1}.total.price&lt;BR /&gt;| eval tot_desync=nb_avail_desync+nb_price_desync&lt;BR /&gt;| stats sum(tot_desync) as total ]&lt;BR /&gt;| eval percent = round(nb_desync*100/total,1)&lt;BR /&gt;| search percent &amp;gt; 0&lt;BR /&gt;| fields - total_Desync , percent,total&lt;/P&gt;&lt;P&gt;Output:&lt;/P&gt;&lt;P&gt;check_ins nb_desync&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="119px"&gt;0&lt;/TD&gt;&lt;TD width="40px"&gt;13&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="119px"&gt;1&lt;/TD&gt;&lt;TD width="40px"&gt;13&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="119px"&gt;2&lt;/TD&gt;&lt;TD width="40px"&gt;13&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sanjana_0-1664289833447.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21704i8BE21F8F5AC2481C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Sanjana_0-1664289833447.png" alt="Sanjana_0-1664289833447.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I am trying to combine both query such that my output should look something as mentioned below:&lt;/P&gt;&lt;P&gt;1st column from 1st query as date&amp;nbsp;&lt;/P&gt;&lt;P&gt;2nd column form 2nd query as nb_desync&lt;/P&gt;&lt;P&gt;datevalue nb_desync&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="61.7222px" height="25px"&gt;2022-09-27&lt;/TD&gt;&lt;TD width="67.3056px" height="25px"&gt;13&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="61.7222px" height="25px"&gt;2022-09-28&lt;/TD&gt;&lt;TD width="67.3056px" height="25px"&gt;13&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="61.7222px" height="25px"&gt;2022-09-29&lt;/TD&gt;&lt;TD width="67.3056px" height="25px"&gt;13&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="61.7222px" height="25px"&gt;2022-09-30&lt;/TD&gt;&lt;TD width="67.3056px" height="25px"&gt;13&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!! Looking for your response.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 14:49:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-json-dymanic-field-extraction/m-p/614767#M213670</guid>
      <dc:creator>Sanjana</dc:creator>
      <dc:date>2022-09-27T14:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk json dymanic field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-json-dymanic-field-extraction/m-p/614773#M213673</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248955"&gt;@Sanjana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please let us know how you are relating 1st query output with 2nd query output? if it is one-to-one mapping then just try the below search.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;YOUR_FIRST_SEARCH
| table datevalue  | eval key=1 | accum key | append [search YOUR_SECOND_SEARCH 
| table check_ins nb_desync | eval key=1 | accum key]
| stats values(*) as * by key
|fields - key&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Sample Search :&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval _raw="datevalue
2022-10-15
2022-10-16
2022-10-17
2022-10-18" 
| multikv forceheader=1 
| table datevalue  | eval key=1 | accum key | append [| makeresults 
| eval _raw="check_ins,nb_desync
0,13
1,13
2,13
3,13" 
| multikv forceheader=1 
| table check_ins nb_desync | eval key=1 | accum key]
| stats values(*) as * by key
|fields - key&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there is some other correlation logic then please share _raw for 2nd query and logic.&lt;/P&gt;&lt;P&gt;KV&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 15:47:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-json-dymanic-field-extraction/m-p/614773#M213673</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2022-09-27T15:47:10Z</dc:date>
    </item>
  </channel>
</rss>

