<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: extracting jvm arguments in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621054#M215886</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/250195"&gt;@pmittal&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if possible, please share a sample of your data that's also useful to create a regex.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 16 Nov 2022 13:28:18 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-11-16T13:28:18Z</dc:date>
    <item>
      <title>How to extract, kv pair from jvm_cmd value &amp; print those in Splunk search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621039#M215876</link>
      <description>&lt;P&gt;raw event&lt;/P&gt;
&lt;P&gt;{... "jvm_cmd":"bin/java -Dp -Dp1=v1-Dp2=v2 -Dq -Dp3=v3 ..."}&lt;/P&gt;
&lt;P&gt;How to extract, kv pair from jvm_cmd value &amp;amp; print those in Splunk search?&lt;/P&gt;
&lt;P&gt;I am not admin. So, I can't change props.conf or transform.conf. I tried&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Using-KV-MODE-auto-in-props-conf-how-do-I-get-a-search-time/m-p/240834" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Splunk-Search/Using-KV-MODE-auto-in-props-conf-how-do-I-get-a-search-time/m-p/240834&lt;/A&gt;&amp;nbsp;and rex without any success. Any help will be much appreciated&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 15:05:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621039#M215876</guid>
      <dc:creator>pmittal</dc:creator>
      <dc:date>2022-11-16T15:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: extracting jvm arguments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621040#M215877</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/250195"&gt;@pmittal&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;it seems to be a json format, did you tried with spath command (&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Spath)?" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Spath)?&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 11:37:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621040#M215877</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-16T11:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: extracting jvm arguments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621045#M215879</link>
      <description>&lt;P&gt;I am not sure how that's gonna solve the problem. I am trying to parse jvm_cmd value and it's not a JSON. Can you share some sample spath if I misunderstood you?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 12:41:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621045#M215879</guid>
      <dc:creator>pmittal</dc:creator>
      <dc:date>2022-11-16T12:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: extracting jvm arguments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621047#M215881</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/250195"&gt;@pmittal&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you can find all the information and samples in the above link.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 13:00:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621047#M215881</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-16T13:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: extracting jvm arguments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621052#M215884</link>
      <description>&lt;P&gt;I tried it before posting without any success. All the example in that link has value itself as either JSON or XML whereas in this case no fixed pattern in value&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 13:26:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621052#M215884</guid>
      <dc:creator>pmittal</dc:creator>
      <dc:date>2022-11-16T13:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: extracting jvm arguments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621054#M215886</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/250195"&gt;@pmittal&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if possible, please share a sample of your data that's also useful to create a regex.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 13:28:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621054#M215886</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-16T13:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: extracting jvm arguments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621055#M215887</link>
      <description>&lt;P&gt;it's there in initial post. I need that P1=v1, p2=v2 ... key pairs extracted&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 13:31:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621055#M215887</guid>
      <dc:creator>pmittal</dc:creator>
      <dc:date>2022-11-16T13:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: extracting jvm arguments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621056#M215888</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/250195"&gt;@pmittal&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;{... "jvm_cmd":"bin/java -Dp -Dp1=v1-Dp2=v2 -Dq -Dp3=v3 ..."} isn't a full log, if possible, share a full log to understand if it's a json.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 13:35:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621056#M215888</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-16T13:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: extracting jvm arguments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621062#M215892</link>
      <description>&lt;P&gt;log entry is a json. i can fetch jvm_cmd parmeter as it is a JSON key. that's not the issue. I need to parse value of jvm_cmd. can't share full log due to sensitive information. I tried following Splunk query (few other variations too). It just print log/raw json fields but it won't extract fields out of jvm_cmd value&lt;/P&gt;&lt;P&gt;index=abc jvm_cmd=*xyz* | spath | table *&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 14:02:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621062#M215892</guid>
      <dc:creator>pmittal</dc:creator>
      <dc:date>2022-11-16T14:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: extracting jvm arguments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621096#M215907</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/250195"&gt;@pmittal&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you're sure that you have a json format the spath command should extract all the fields, also the one you need.&lt;/P&gt;&lt;P&gt;If you want to extract only one field, you could follow the 5th example of the link&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Spath" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Spath&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Could you mask a sample of your data to share?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 16:24:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621096#M215907</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-16T16:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: extracting jvm arguments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621109#M215914</link>
      <description>&lt;P&gt;I don't have to retrieve field value. I have to retrieve key value pair located inside field value. Either you are not getting my point or I am not getting yours at all. Please see java_cmd param value. need to get K,V pair out of it&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 17:03:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621109#M215914</guid>
      <dc:creator>pmittal</dc:creator>
      <dc:date>2022-11-16T17:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract, kv pair from jvm_cmd value &amp; print those in Splunk search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621201#M215941</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/250195"&gt;@pmittal&lt;/a&gt;&amp;nbsp;Are you thinking of kv aka &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Extract" target="_blank" rel="noopener"&gt;extract&lt;/A&gt;?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rename _raw as tmp, jvm_cmd as _raw
| kv pairdelim="-"
| rename D* as *&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 08:46:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/621201#M215941</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-11-17T08:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract, kv pair from jvm_cmd value &amp; print those in Splunk search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/623211#M216652</link>
      <description>&lt;P&gt;Apologies for the delayed response. I used REX meanwhile to extract required fields but it was not a full proof solution because I should know fields to be extracted in advance which is not possible. This is where &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt; solution worked as expected.&lt;/P&gt;&lt;P&gt;One final clarification - This solution worked only if jvm_cmd is renamed as _raw. Is it possible to avoid renaming and worked directly on jvm_cmd?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 10:23:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/623211#M216652</guid>
      <dc:creator>pmittal</dc:creator>
      <dc:date>2022-12-05T10:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract, kv pair from jvm_cmd value &amp; print those in Splunk search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/623311#M216677</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;One final clarification - This solution worked only if jvm_cmd is renamed as _raw. Is it possible to avoid renaming and worked directly on jvm_cmd?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;To be honest, there were multiple times I wished that was possible but no. However, in your case, the JSON object is already in _raw. You can try your luck by simply apply &lt;FONT face="andale mono,times"&gt;| kv&lt;/FONT&gt; without any predisposition. The worst that can happen is that, in addition to possibly extracting additional fields from other JSON nodes that may contain equal-sign-separated kv pairs, some of these interfere with those pairs in jvm_cmd. So, manually test with a meaningful amount of sample. (Or ask your developer if any other fields can potentially contain equal-sign-separated pair and can potentially have overlapping keys.)&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 19:11:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-pair-from-jvm-cmd-value-amp-print-those-in/m-p/623311#M216677</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-12-05T19:11:01Z</dc:date>
    </item>
  </channel>
</rss>

