<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Retrive data form keys value in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622782#M216516</link>
    <description>&lt;P&gt;not working.&lt;/P&gt;&lt;P&gt;my query is : table cxlBusinessData.data.body| spath | spath input=body | spath input=Message&lt;/P&gt;</description>
    <pubDate>Thu, 01 Dec 2022 10:06:44 GMT</pubDate>
    <dc:creator>prashantsagar73</dc:creator>
    <dc:date>2022-12-01T10:06:44Z</dc:date>
    <item>
      <title>How to retrieve data form keys value?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622772#M216511</link>
      <description>&lt;P&gt;i have a table who contain multiple keys and value one of them &lt;STRONG&gt;keys{"body"}&lt;/STRONG&gt; value are below:&lt;/P&gt;
&lt;P class="lia-align-left"&gt;"body": "{\n \"Type\" : \"Notification\",\n \"MessageId\" : \"f33b9756-bc6b-5efc-8111-cca792b8d4f3\",\n \"TopicArn\" : \"arn:aws:sns:eu-central-1:108770896200:PL-PRD-notification-media\",\n \"Message\" : \"{\\\"licenseValidFrom\\\":\\\"2022-11-18T07:56:18.760+01:00\\\",\\\"licenseValidUntil\\\": \\\"3022-03-21T07:56:18.760+01:00\\\",\\\"hasCopyright\\\":\\\"False\\\",\\\"resolutionInPx\\\": \\\"685x1664\\\",\\\"resolutionKey\\\":\\\"ORIGINAL\\\",\\\"checksum\\\":\\\"35a63f43ec3088c9cf01b6c5473f1436\\\", \\\"description\\\": \\\"Jewelry Full\\\", \\\"brand\\\": \\\"\\\", \\\"category\\\": \\\"\\\", \\\"mediaType\\\": \\\"AdditionalImage\\\", \\\"status\\\": \\\"Media.Active.490.Finished\\\", \\\&lt;STRONG&gt;"gtin\\\": \\\"9009656409602\\\"&lt;/STRONG&gt;, \\\"channel\\\": \\\"gkkDigitalDataManagement\\\", \\\"mediaId\\\": \\\"06\\\", \\\"contentType\\\": \\\"image/jpeg\\\"}\",\n \"Timestamp\" : \"2022-11-18T06:56:19.980Z\",\n \"SignatureVersion\" : \"1\",\n \"Signature\" : \"AySfxHK6Y3ZSA7BsgR7sFHva82snBuenk74ZMJ5HzewU4ozOg8PDOnjeBAY0FLbFxomWOEVIzNWp9yW8Ti9lWWNpdzeMd4MYUhN/a0tLwce1Dk0xdAlsM9DByiJHUTWj1QkvUsaJChMaDfZOyFwZNhvHBbtC9W/Y9AtcZnS9ahz8bQBvxIZv/Xb7tK/g0pvOJ2Nx633TN1UStYshQef8g1cV+q4Ey0fMRr9l/K00POuBUCcGZRRXTiGaqVOTWk08ARFsW5a9Iz28kaBz4PDFNdCALgnwdZ65m6k2HL8fYW5O7gvxEqAOLnYcPsX8XLiV20tSd2NBgoytq5f3IxAbsw==\",\n \"MessageAttributes\" : {\n \"channel\" : {\"Type\":\"String\",\"Value\":\"gkkDigitalDataManagement\"},\n \"mediaStatus\" : {\"Type\":\"String\",\"Value\":\"Media.Active.490.Finished\"},\n \"mediaType\" : {\"Type\":\"String\",\"Value\":\"AdditionalImage\"}\n }\n}",&lt;/P&gt;
&lt;P class="lia-align-left"&gt; &lt;/P&gt;
&lt;P class="lia-align-left"&gt;want to retrieve [gtin: 9009656409602] in a separate table&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 16:05:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622772#M216511</guid>
      <dc:creator>prashantsagar73</dc:creator>
      <dc:date>2022-12-01T16:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: Retrive data form keys value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622778#M216513</link>
      <description>&lt;P&gt;Since you have escaped embedded JSON, you could try extracting in stages.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| spath
| spath input=body
| spath input=Message&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 01 Dec 2022 09:12:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622778#M216513</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-12-01T09:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: Retrive data form keys value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622782#M216516</link>
      <description>&lt;P&gt;not working.&lt;/P&gt;&lt;P&gt;my query is : table cxlBusinessData.data.body| spath | spath input=body | spath input=Message&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 10:06:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622782#M216516</guid>
      <dc:creator>prashantsagar73</dc:creator>
      <dc:date>2022-12-01T10:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: Retrive data form keys value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622784#M216517</link>
      <description>&lt;P&gt;Sounds like your raw event is not pure JSON - please can you share an anonymised version of your raw events in a code block &amp;lt;/&amp;gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 10:19:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622784#M216517</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-12-01T10:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: Retrive data form keys value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622787#M216520</link>
      <description>&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 11:56:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622787#M216520</guid>
      <dc:creator>prashantsagar73</dc:creator>
      <dc:date>2022-12-01T11:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: Retrive data form keys value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622788#M216521</link>
      <description>&lt;P&gt;the previous result was belong from this data body&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 10:30:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622788#M216521</guid>
      <dc:creator>prashantsagar73</dc:creator>
      <dc:date>2022-12-01T10:30:00Z</dc:date>
    </item>
    <item>
      <title>Re: Retrive data form keys value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622789#M216522</link>
      <description>&lt;P&gt;Which field is this data extracted to - for example if it was called body&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| spath input=body
| spath input=cxlBusinessData.data.body
| spath input=Message&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 01 Dec 2022 10:39:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622789#M216522</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-12-01T10:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: Retrive data form keys value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622790#M216523</link>
      <description>&lt;P&gt;it gives u the same output like before one if u call body.&lt;/P&gt;&lt;P&gt;my code :&lt;/P&gt;&lt;P&gt;| table cxlBusinessData.data.body&lt;/P&gt;&lt;P&gt;this one gives me the body part(output) only that i attached with the question, but from that body i want data{ gtin} in a separate table. so i can use it further .&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 10:48:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622790#M216523</guid>
      <dc:creator>prashantsagar73</dc:creator>
      <dc:date>2022-12-01T10:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: Retrive data form keys value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622796#M216526</link>
      <description>&lt;P&gt;You need to remove spurious characters first.&lt;/P&gt;&lt;PRE&gt;| eval "cxlBusinessData.data.body" = replace('c', "\\\n ", "")
| spath input=cxlBusinessData.data.body
| spath input=Message
| table gtin&lt;/PRE&gt;</description>
      <pubDate>Thu, 01 Dec 2022 11:15:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-retrieve-data-form-keys-value/m-p/622796#M216526</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-12-01T11:15:23Z</dc:date>
    </item>
  </channel>
</rss>

