<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: extract fields in json format in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626289#M217671</link>
    <description>&lt;P&gt;You won't get it from extract command because that part is not in any key-value pair that you can define. &amp;nbsp;It is in the fourth bracket that come before all the key-value pairs. &amp;nbsp;You'll need to first separate the two parts, then get the content of those brackets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval log = split(log, " - ") ``` structure before " - " and after are fundamentally different ```
| eval bracketed = split(mvindex(log, 0), "] [") ``` this part contains brackets ```
| eval keyvalue = mvindex(log, 1) ``` this part contains key-value pairs ```
| rename keyvalue AS _raw ``` for simplicity, we don't care about original _raw here ```
| kv
| eval ccnteiT = mvindex(bracketed, 3) ``` this is the part of your interest ```
| rex field=ccnteiT "(?&amp;lt;THEfield&amp;gt;\w+)$" ``` THEfield contains the interested value ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using your sample data, you get&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;THEfield&lt;/TD&gt;&lt;TD&gt;apiVersion&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;bracketed&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;category&lt;/TD&gt;&lt;TD&gt;ccnteiT&lt;/TD&gt;&lt;TD&gt;channel&lt;/TD&gt;&lt;TD&gt;code&lt;/TD&gt;&lt;TD&gt;component&lt;/TD&gt;&lt;TD&gt;entityType&lt;/TD&gt;&lt;TD&gt;eventDateTime&lt;/TD&gt;&lt;TD&gt;eventName&lt;/TD&gt;&lt;TD&gt;externalSystem&lt;/TD&gt;&lt;TD&gt;message&lt;/TD&gt;&lt;TD&gt;messageIdentification&lt;/TD&gt;&lt;TD&gt;producer&lt;/TD&gt;&lt;TD&gt;productVersion&lt;/TD&gt;&lt;TD&gt;serviceName&lt;/TD&gt;&lt;TD&gt;severity&lt;/TD&gt;&lt;TD&gt;start&lt;/TD&gt;&lt;TD&gt;subscriptionIdentification&lt;/TD&gt;&lt;TD&gt;swiftMessagePartnerBIC&lt;/TD&gt;&lt;TD&gt;url&lt;/TD&gt;&lt;TD&gt;uuid&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ServiceCalloutEventData&lt;/TD&gt;&lt;TD&gt;V1&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;[18:15:21.888&lt;/DIV&gt;&lt;DIV class=""&gt;INFO&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;c.c.n.t.e.i.T.ServiceCalloutEventData&lt;/DIV&gt;&lt;DIV class=""&gt;akka://MmsAuCluster/user/$b/workMonitorActor/$M+c]&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;integrational-external&lt;/TD&gt;&lt;TD&gt;c.c.n.t.e.i.T.ServiceCalloutEventData&lt;/TD&gt;&lt;TD&gt;AutoNotification&lt;/TD&gt;&lt;TD&gt;ServiceCalloutEventData&lt;/TD&gt;&lt;TD&gt;web.client&lt;/TD&gt;&lt;TD&gt;MNDT&lt;/TD&gt;&lt;TD&gt;2023-01-06T07:15:21.888Z&lt;/TD&gt;&lt;TD&gt;MANDATE_NOTIFICATION_RETRIEVAL.CALLOUT_REQUEST&lt;/TD&gt;&lt;TD&gt;SWIFTPAG&lt;/TD&gt;&lt;TD&gt;Schedule Job start, getNotification request&lt;/TD&gt;&lt;TD&gt;e1f24a3b8d9111edb3368d1476d87136&lt;/TD&gt;&lt;TD&gt;com.clear2pay.na.mms.au.notification.batch.GetNotificationService&lt;/TD&gt;&lt;TD&gt;2.3.3-0-1-eb5b8cadd&lt;/TD&gt;&lt;TD&gt;Consume Notification&lt;/TD&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;1672989321888&lt;/TD&gt;&lt;TD&gt;29fbe070057811eca4fa68aa418f5c2a&lt;/TD&gt;&lt;TD&gt;RESTMP01&lt;/TD&gt;&lt;TD&gt;&lt;A href="https://sandbox.swift.com/npp-mms/v1/subscriptions/29fbe070057811eca4fa68aa418f5c2a/notifications" target="_blank" rel="noopener"&gt;https://sandbox.swift.com/npp-mms/v1/subscriptions/29fbe070057811eca4fa68aa418f5c2a/notifications&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;0b8549ff-1f14-4fd5-99c5-b3f2240d7da8&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;If you need content from any other brackets, you can still use mvindex on bracketed.&lt;/P&gt;</description>
    <pubDate>Sat, 07 Jan 2023 07:12:04 GMT</pubDate>
    <dc:creator>yuanliu</dc:creator>
    <dc:date>2023-01-07T07:12:04Z</dc:date>
    <item>
      <title>How to extract fields in json format?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626110#M217625</link>
      <description>&lt;P&gt;i need to extract fields which are in json format i have been trying using spath command for extracting the following fields which are under log. But not able to fetch it. I am failing somewhere.&lt;BR /&gt;Here is the example of my data:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;log&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"[&lt;/SPAN&gt;&lt;SPAN class=""&gt;18:15:21.888&lt;/SPAN&gt;&lt;SPAN&gt;] [&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt; ] [] [&lt;/SPAN&gt;&lt;SPAN class=""&gt;c.c.n.t.e.i.T.ServiceCalloutEventData&lt;/SPAN&gt;&lt;SPAN&gt;] [&lt;/SPAN&gt;&lt;SPAN class=""&gt;akka://MmsAuCluster/user/$b/workMonitorActor/$M&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;c&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;channel=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;AutoNotification\&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;productVersion=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;2.3.3-0-1-eb5b8cadd\&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;apiVersion=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;V1\&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;uuid=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;0b8549ff-1f14-4fd5-99c5-b3f2240d7da8\&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;eventDateTime=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;2023-01-06T07:15:21.888Z\&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;severity=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt;\&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;code=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;ServiceCalloutEventData\&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;component=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;web.client\&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;category=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;integrational-external\&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;serviceName=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Consume&lt;/SPAN&gt; &lt;SPAN class=""&gt;Notification\&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;eventName=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;MANDATE_NOTIFICATION_RETRIEVAL.CALLOUT_REQUEST\&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;message=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Schedule&lt;/SPAN&gt; &lt;SPAN class=""&gt;Job&lt;/SPAN&gt; &lt;SPAN class=""&gt;start&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;getNotification&lt;/SPAN&gt; &lt;SPAN class=""&gt;request\&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;entityType=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;MNDT&lt;/SPAN&gt;\&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;externalSystem=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;SWIFTPAG\&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;start=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;1672989321888\&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;url=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A href="https://sandbox.swift.com/npp-mms/v1/subscriptions/29fbe070057811eca4fa68aa418f5c2a/notifications\" target="_blank" rel="noopener"&gt;https://sandbox.swift.com/npp-mms/v1/subscriptions/29fbe070057811eca4fa68aa418f5c2a/notifications\&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;swiftMessagePartnerBIC=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;RESTMP01\&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;messageIdentification=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;e1f24a3b8d9111edb3368d1476d87136\&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;subscriptionIdentification=\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;29fbe070057811eca4fa68aa418f5c2a\&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;producer=com.clear2pay.na.mms.au.notification.batch.GetNotificationService&lt;/SPAN&gt; &lt;SPAN class=""&gt;\n&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;stream&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;stdout&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;docker&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;container_id&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;89efc58c0a343ee01daa2fcdeadb3b952599f0c142fb7041f95a9d6702fe49d2&lt;/SPAN&gt;&lt;SPAN&gt;"},"&lt;/SPAN&gt;&lt;SPAN class=""&gt;kubernetes&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;container_name&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;mms-au&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;namespace_name&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;msaas-t4&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;pod_name&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;mms-au-b-1-54b4589f89-g74lp&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;container_image&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;pso.docker.internal.cba/mms-au:2.3.3-0-1-eb5b8cadd&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;container_image_id&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;docker-pullable://pso.docker.internal.cba/mms-au@sha256:9d48d5af268d28708120ee3f69b576d371b5e603a0e0c925c7dba66058654819&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;pod_id&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;b474ec16-fc9f-4b7a-9319-8302c0185f83&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;pod_ip&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;100.64.87.219&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;host&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;ip-10-3-197-177.ap-southeast-2.compute.internal&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;labels&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;app&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;mms-au&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;dc&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;b-1&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;pod-template-hash&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;54b4589f89&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;release&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;mms-au&lt;/SPAN&gt;&lt;SPAN&gt;"},"&lt;/SPAN&gt;&lt;SPAN class=""&gt;master_url&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A href="https://172.20.0.1:443/api" target="_blank" rel="noopener"&gt;https://172.20.0.1:443/api&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;namespace_id&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;48ee871a-7e60-45c4-b0f4-ee320a9512f5&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;namespace_labels&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;argocd.argoproj.io/instance&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;appspaces&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;ci&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;CM0953076&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;kubernetes.io/metadata.name&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;msaas-t4&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;msaas-t4&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;platform&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;PSU&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;service_owner&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;somersd&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;spg&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;CBA_PAYMENTS_TEST_COORDINATION&lt;/SPAN&gt;&lt;SPAN&gt;"}},"&lt;/SPAN&gt;&lt;SPAN class=""&gt;hostname&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;ip-10-3-197-177.ap-southeast-2.compute.internal&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;host_ip&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;10.3.197.177&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;cluster&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;nonprod/pmn02&lt;/SPAN&gt;&lt;SPAN&gt;"}&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;i need to extract few events which are under log.Can anyone help me on this.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in Advance&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 14:00:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626110#M217625</guid>
      <dc:creator>vineela</dc:creator>
      <dc:date>2023-01-06T14:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: extract fields in json format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626117#M217629</link>
      <description>&lt;P&gt;I see no problem with spath if I just plug your sample. &amp;nbsp;(In fact, if that's your raw event, you shouldn't need spath at all. &amp;nbsp;Splunk should have already extracted all JSON nodes for you.) &amp;nbsp;Do you mean that you want to extract key-value pair in the "log" field? &amp;nbsp;You need &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Extract" target="_blank" rel="noopener"&gt;extract&lt;/A&gt; (aka kv) command.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rename _raw as temp, log as _raw
| kv
| rename temp as _raw ``` we are losing log by not renaming _raw back ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Excluding all original JSON fields and _raw, the output from your sample would be&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;apiVersion&lt;/TD&gt;&lt;TD&gt;category&lt;/TD&gt;&lt;TD&gt;channel&lt;/TD&gt;&lt;TD&gt;code&lt;/TD&gt;&lt;TD&gt;component&lt;/TD&gt;&lt;TD&gt;entityType&lt;/TD&gt;&lt;TD&gt;eventDateTime&lt;/TD&gt;&lt;TD&gt;eventName&lt;/TD&gt;&lt;TD&gt;externalSystem&lt;/TD&gt;&lt;TD&gt;message&lt;/TD&gt;&lt;TD&gt;messageIdentification&lt;/TD&gt;&lt;TD&gt;producer&lt;/TD&gt;&lt;TD&gt;productVersion&lt;/TD&gt;&lt;TD&gt;serviceName&lt;/TD&gt;&lt;TD&gt;severity&lt;/TD&gt;&lt;TD&gt;start&lt;/TD&gt;&lt;TD&gt;subscriptionIdentification&lt;/TD&gt;&lt;TD&gt;swiftMessagePartnerBIC&lt;/TD&gt;&lt;TD&gt;url&lt;/TD&gt;&lt;TD&gt;uuid&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;V1&lt;/TD&gt;&lt;TD&gt;integrational-external&lt;/TD&gt;&lt;TD&gt;AutoNotification&lt;/TD&gt;&lt;TD&gt;ServiceCalloutEventData&lt;/TD&gt;&lt;TD&gt;web.client&lt;/TD&gt;&lt;TD&gt;MNDT&lt;/TD&gt;&lt;TD&gt;2023-01-06T07:15:21.888Z&lt;/TD&gt;&lt;TD&gt;MANDATE_NOTIFICATION_RETRIEVAL.CALLOUT_REQUEST&lt;/TD&gt;&lt;TD&gt;SWIFTPAG&lt;/TD&gt;&lt;TD&gt;Schedule Job start, getNotification request&lt;/TD&gt;&lt;TD&gt;e1f24a3b8d9111edb3368d1476d87136&lt;/TD&gt;&lt;TD&gt;com.clear2pay.na.mms.au.notification.batch.GetNotificationService&lt;/TD&gt;&lt;TD&gt;2.3.3-0-1-eb5b8cadd&lt;/TD&gt;&lt;TD&gt;Consume Notification&lt;/TD&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;1672989321888&lt;/TD&gt;&lt;TD&gt;29fbe070057811eca4fa68aa418f5c2a&lt;/TD&gt;&lt;TD&gt;RESTMP01&lt;/TD&gt;&lt;TD&gt;&lt;A href="https://sandbox.swift.com/npp-mms/v1/subscriptions/29fbe070057811eca4fa68aa418f5c2a/notifications" target="_blank" rel="noopener"&gt;https://sandbox.swift.com/npp-mms/v1/subscriptions/29fbe070057811eca4fa68aa418f5c2a/notifications&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;0b8549ff-1f14-4fd5-99c5-b3f2240d7da8&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Here is an emulated test for you to play with and compare with your actual data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| fields - _time
| eval _raw = "{\"log\":\"[18:15:21.888] [INFO ] [] [c.c.n.t.e.i.T.ServiceCalloutEventData] [akka://MmsAuCluster/user/$b/workMonitorActor/$M+c] - channel=\\\"AutoNotification\\\", productVersion=\\\"2.3.3-0-1-eb5b8cadd\\\", apiVersion=\\\"V1\\\", uuid=\\\"0b8549ff-1f14-4fd5-99c5-b3f2240d7da8\\\", eventDateTime=\\\"2023-01-06T07:15:21.888Z\\\", severity=\\\"INFO\\\", code=\\\"ServiceCalloutEventData\\\", component=\\\"web.client\\\", category=\\\"integrational-external\\\", serviceName=\\\"Consume Notification\\\", eventName=\\\"MANDATE_NOTIFICATION_RETRIEVAL.CALLOUT_REQUEST\\\", message=\\\"Schedule Job start, getNotification request\\\", entityType=\\\"MNDT\\\", externalSystem=\\\"SWIFTPAG\\\", start=\\\"1672989321888\\\", url=\\\"https://sandbox.swift.com/npp-mms/v1/subscriptions/29fbe070057811eca4fa68aa418f5c2a/notifications\\\", swiftMessagePartnerBIC=\\\"RESTMP01\\\", messageIdentification=\\\"e1f24a3b8d9111edb3368d1476d87136\\\", subscriptionIdentification=\\\"29fbe070057811eca4fa68aa418f5c2a\\\" producer=com.clear2pay.na.mms.au.notification.batch.GetNotificationService \\n\",\"stream\":\"stdout\",\"docker\":{\"container_id\":\"89efc58c0a343ee01daa2fcdeadb3b952599f0c142fb7041f95a9d6702fe49d2\"},\"kubernetes\":{\"container_name\":\"mms-au\",\"namespace_name\":\"msaas-t4\",\"pod_name\":\"mms-au-b-1-54b4589f89-g74lp\",\"container_image\":\"pso.docker.internal.cba/mms-au:2.3.3-0-1-eb5b8cadd\",\"container_image_id\":\"docker-pullable://pso.docker.internal.cba/mms-au@sha256:9d48d5af268d28708120ee3f69b576d371b5e603a0e0c925c7dba66058654819\",\"pod_id\":\"b474ec16-fc9f-4b7a-9319-8302c0185f83\",\"pod_ip\":\"100.64.87.219\",\"host\":\"ip-10-3-197-177.ap-southeast-2.compute.internal\",\"labels\":{\"app\":\"mms-au\",\"dc\":\"b-1\",\"pod-template-hash\":\"54b4589f89\",\"release\":\"mms-au\"},\"master_url\":\"https://172.20.0.1:443/api\",\"namespace_id\":\"48ee871a-7e60-45c4-b0f4-ee320a9512f5\",\"namespace_labels\":{\"argocd.argoproj.io/instance\":\"appspaces\",\"ci\":\"CM0953076\",\"kubernetes.io/metadata.name\":\"msaas-t4\",\"name\":\"msaas-t4\",\"platform\":\"PSU\",\"service_owner\":\"somersd\",\"spg\":\"CBA_PAYMENTS_TEST_COORDINATION\"}},\"hostname\":\"ip-10-3-197-177.ap-southeast-2.compute.internal\",\"host_ip\":\"10.3.197.177\",\"cluster\":\"nonprod/pmn02\"}"
| spath
``` data emulation above ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 08:13:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626117#M217629</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-01-06T08:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: extract fields in json format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626125#M217632</link>
      <description>&lt;P&gt;Hi Yuanliu,&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Thanks for your reply.&lt;BR /&gt;May be ia m using in wrong way or not i am not sure..i am not able to fetch results using your command.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vineela_0-1672999993391.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23229iA5FE51E2FCC629E2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vineela_0-1672999993391.png" alt="vineela_0-1672999993391.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And i tried using makeresults but my requirement is to fetch details from log events...i mean key value pairs which are present under field log.Can you please help me on the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 10:14:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626125#M217632</guid>
      <dc:creator>vineela</dc:creator>
      <dc:date>2023-01-06T10:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: extract fields in json format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626285#M217667</link>
      <description>&lt;P&gt;Have you tried my code? &amp;nbsp;That is to extract key-value pair in the field log.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 03:00:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626285#M217667</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-01-07T03:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: extract fields in json format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626286#M217668</link>
      <description>&lt;P&gt;Yes i tried but not able to fetch results .i shared screenshot as well.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 03:02:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626286#M217668</guid>
      <dc:creator>vineela</dc:creator>
      <dc:date>2023-01-07T03:02:46Z</dc:date>
    </item>
    <item>
      <title>Re: extract fields in json format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626287#M217669</link>
      <description>&lt;P&gt;The pairs are extracted; you can't see then because you are in "Fast mode". &amp;nbsp;If you switch to "Smart mode" or "Verbose mode", you'll see them listed in the left. &amp;nbsp;But you can also just table those columns, like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rename _raw as temp, log as _raw
| kv
| rename temp as _raw ``` we are losing log by not renaming _raw back ```
| fields - _raw log ``` so the very long logs are not clogging view ```
| table *&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 03:08:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626287#M217669</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-01-07T03:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: extract fields in json format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626288#M217670</link>
      <description>&lt;P&gt;Yes, i am able to see results now. But again one more issue i am facing i need to extract "ServiceCalloutEventData" field - which is highlighted under,it is not extracted as key value pair from log.&lt;BR /&gt;&lt;BR /&gt;here is the sample log:&amp;nbsp;log\":\"[18:15:21.888] [INFO ] [] [&lt;STRONG&gt;c.c.n.t.e.i.T.ServiceCalloutEventData&lt;/STRONG&gt;] [akka://MmsAuCluster/user/$b/workMonitorActor/$M+c] - channel=\\\"AutoNotification\\\", productVersion=\\\"2.3.3-0-1-eb5b8cadd\\\", apiVersion=\\\"V1\\\", uuid=\\\"0b8549ff-1f14-4fd5-99c5-b3f2240d7da8\\\", eventDateTime=\\\"2023-01-06T07:15:21.888Z\\\", severity=\\\"INFO&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 04:28:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626288#M217670</guid>
      <dc:creator>vineela</dc:creator>
      <dc:date>2023-01-07T04:28:26Z</dc:date>
    </item>
    <item>
      <title>Re: extract fields in json format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626289#M217671</link>
      <description>&lt;P&gt;You won't get it from extract command because that part is not in any key-value pair that you can define. &amp;nbsp;It is in the fourth bracket that come before all the key-value pairs. &amp;nbsp;You'll need to first separate the two parts, then get the content of those brackets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval log = split(log, " - ") ``` structure before " - " and after are fundamentally different ```
| eval bracketed = split(mvindex(log, 0), "] [") ``` this part contains brackets ```
| eval keyvalue = mvindex(log, 1) ``` this part contains key-value pairs ```
| rename keyvalue AS _raw ``` for simplicity, we don't care about original _raw here ```
| kv
| eval ccnteiT = mvindex(bracketed, 3) ``` this is the part of your interest ```
| rex field=ccnteiT "(?&amp;lt;THEfield&amp;gt;\w+)$" ``` THEfield contains the interested value ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using your sample data, you get&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;THEfield&lt;/TD&gt;&lt;TD&gt;apiVersion&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;bracketed&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;category&lt;/TD&gt;&lt;TD&gt;ccnteiT&lt;/TD&gt;&lt;TD&gt;channel&lt;/TD&gt;&lt;TD&gt;code&lt;/TD&gt;&lt;TD&gt;component&lt;/TD&gt;&lt;TD&gt;entityType&lt;/TD&gt;&lt;TD&gt;eventDateTime&lt;/TD&gt;&lt;TD&gt;eventName&lt;/TD&gt;&lt;TD&gt;externalSystem&lt;/TD&gt;&lt;TD&gt;message&lt;/TD&gt;&lt;TD&gt;messageIdentification&lt;/TD&gt;&lt;TD&gt;producer&lt;/TD&gt;&lt;TD&gt;productVersion&lt;/TD&gt;&lt;TD&gt;serviceName&lt;/TD&gt;&lt;TD&gt;severity&lt;/TD&gt;&lt;TD&gt;start&lt;/TD&gt;&lt;TD&gt;subscriptionIdentification&lt;/TD&gt;&lt;TD&gt;swiftMessagePartnerBIC&lt;/TD&gt;&lt;TD&gt;url&lt;/TD&gt;&lt;TD&gt;uuid&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ServiceCalloutEventData&lt;/TD&gt;&lt;TD&gt;V1&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;[18:15:21.888&lt;/DIV&gt;&lt;DIV class=""&gt;INFO&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;c.c.n.t.e.i.T.ServiceCalloutEventData&lt;/DIV&gt;&lt;DIV class=""&gt;akka://MmsAuCluster/user/$b/workMonitorActor/$M+c]&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;integrational-external&lt;/TD&gt;&lt;TD&gt;c.c.n.t.e.i.T.ServiceCalloutEventData&lt;/TD&gt;&lt;TD&gt;AutoNotification&lt;/TD&gt;&lt;TD&gt;ServiceCalloutEventData&lt;/TD&gt;&lt;TD&gt;web.client&lt;/TD&gt;&lt;TD&gt;MNDT&lt;/TD&gt;&lt;TD&gt;2023-01-06T07:15:21.888Z&lt;/TD&gt;&lt;TD&gt;MANDATE_NOTIFICATION_RETRIEVAL.CALLOUT_REQUEST&lt;/TD&gt;&lt;TD&gt;SWIFTPAG&lt;/TD&gt;&lt;TD&gt;Schedule Job start, getNotification request&lt;/TD&gt;&lt;TD&gt;e1f24a3b8d9111edb3368d1476d87136&lt;/TD&gt;&lt;TD&gt;com.clear2pay.na.mms.au.notification.batch.GetNotificationService&lt;/TD&gt;&lt;TD&gt;2.3.3-0-1-eb5b8cadd&lt;/TD&gt;&lt;TD&gt;Consume Notification&lt;/TD&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;1672989321888&lt;/TD&gt;&lt;TD&gt;29fbe070057811eca4fa68aa418f5c2a&lt;/TD&gt;&lt;TD&gt;RESTMP01&lt;/TD&gt;&lt;TD&gt;&lt;A href="https://sandbox.swift.com/npp-mms/v1/subscriptions/29fbe070057811eca4fa68aa418f5c2a/notifications" target="_blank" rel="noopener"&gt;https://sandbox.swift.com/npp-mms/v1/subscriptions/29fbe070057811eca4fa68aa418f5c2a/notifications&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;0b8549ff-1f14-4fd5-99c5-b3f2240d7da8&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;If you need content from any other brackets, you can still use mvindex on bracketed.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 07:12:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626289#M217671</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-01-07T07:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: extract fields in json format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626378#M217711</link>
      <description>&lt;P&gt;Thanks Splunk champion..That was very clear...I Saw many videos for learning spath command and your solution for my question was crisp and clear...Easily understandable.Very helpful.Thanks a lot again.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 09:02:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-in-json-format/m-p/626378#M217711</guid>
      <dc:creator>vineela</dc:creator>
      <dc:date>2023-01-09T09:02:16Z</dc:date>
    </item>
  </channel>
</rss>

