<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Parsing string with whitespaces as json object in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Parsing-string-with-whitespaces-as-json-object/m-p/688803#M234798</link>
    <description>&lt;P&gt;Hi, I am completely new to splunk and have to parse field that looks like this:&lt;BR /&gt;params="['field1: value1', 'field2: value2', 'field3: value3']" (note spaces after colons) - I have to extract field1, field2, field3 to be searchable - can you help with what query should I write?&lt;/P&gt;</description>
    <pubDate>Mon, 27 May 2024 18:13:41 GMT</pubDate>
    <dc:creator>mipa04</dc:creator>
    <dc:date>2024-05-27T18:13:41Z</dc:date>
    <item>
      <title>Parsing string with whitespaces as json object</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Parsing-string-with-whitespaces-as-json-object/m-p/688803#M234798</link>
      <description>&lt;P&gt;Hi, I am completely new to splunk and have to parse field that looks like this:&lt;BR /&gt;params="['field1: value1', 'field2: value2', 'field3: value3']" (note spaces after colons) - I have to extract field1, field2, field3 to be searchable - can you help with what query should I write?&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 18:13:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Parsing-string-with-whitespaces-as-json-object/m-p/688803#M234798</guid>
      <dc:creator>mipa04</dc:creator>
      <dc:date>2024-05-27T18:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing string with whitespaces as json object</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Parsing-string-with-whitespaces-as-json-object/m-p/688811#M234804</link>
      <description>&lt;P&gt;That isn't a JSON object, so you could try using rex to parse it - you could try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex max_match=0 "'(?&amp;lt;field&amp;gt;\w+:\s[^']+)'"
| mvexpand field
| rex field=field "(?&amp;lt;name&amp;gt;\w+):\s(?&amp;lt;value&amp;gt;.*)"
| eval {name} = value
| fields - name value
| stats values(*) as * by _raw&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 22:35:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Parsing-string-with-whitespaces-as-json-object/m-p/688811#M234804</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-05-27T22:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing string with whitespaces as json object</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Parsing-string-with-whitespaces-as-json-object/m-p/688945#M234824</link>
      <description>&lt;P&gt;Like&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;said, this is not JSON. &amp;nbsp;AND a strange choice of data format. &amp;nbsp;How to extract what you need depends quite on string values of "field1" "field2", "value1", "value2", etc. &amp;nbsp;If none of "fieldN", "valueN" contains hard breakers such as white space, you do something as simple as&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex mode=sed field=params "s/: */=/g"
| rename _raw as temp, params AS _raw
| kv
| rename temp AS _raw&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(I assume that you already have the field params.)&lt;/P&gt;&lt;P&gt;If the data is more complex than that, you will need to reconstruct data. &amp;nbsp;One way is to convert the structure into conformant JSON. &amp;nbsp;For example,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex mode=sed field=params "s/'/\"/g s/ *: */\":\"/g s/\[/{/ s/]/}/"
| spath input=params&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a complete emulation&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| fields - _*
| eval params = "['field1: value1', 'field2: value2', 'field3: value3']"
| rex mode=sed field=params "s/'/\"/g s/ *: */\":\"/g s/\[/{/ s/]/}/"
| spath input=params&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE width="558px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;field1&lt;/TD&gt;&lt;TD&gt;field2&lt;/TD&gt;&lt;TD&gt;field3&lt;/TD&gt;&lt;TD&gt;params&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="59px"&gt;value1&lt;/TD&gt;&lt;TD width="59px"&gt;value2&lt;/TD&gt;&lt;TD width="59px"&gt;value3&lt;/TD&gt;&lt;TD width="380.015625px"&gt;{"field1":"value1", "field2":"value2", "field3":"value3"}&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 29 May 2024 04:42:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Parsing-string-with-whitespaces-as-json-object/m-p/688945#M234824</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-05-29T04:42:58Z</dc:date>
    </item>
  </channel>
</rss>

