<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Some fields are not extracted in json in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Some-fields-are-not-extracted-in-json/m-p/754334#M242853</link>
    <description>&lt;P&gt;Is this really what your event looks like? I would have expected the namespace to have escaped double quotes, not escaped backslashes?&lt;/P&gt;&lt;P&gt;Please share your raw event is a code block to prevent any undue reformatting of the data.&lt;/P&gt;</description>
    <pubDate>Wed, 15 Oct 2025 07:31:02 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2025-10-15T07:31:02Z</dc:date>
    <item>
      <title>Some fields are not extracted in json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Some-fields-are-not-extracted-in-json/m-p/754280#M242843</link>
      <description>&lt;P&gt;i have json event in that some fields not extracting properly when i am table i am not getting some field after message field ex event&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;here is event and table results&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;{&lt;BR /&gt;"log":{&lt;BR /&gt;"emmsite":"Test",&lt;BR /&gt;"destsite":null,&lt;BR /&gt;"side":"INB",&lt;BR /&gt;"datetime":"10/14/2025 19:14:05",&lt;BR /&gt;"interfaceid":"TI000",&lt;BR /&gt;"env":"dev",&lt;BR /&gt;"objectid":null,&lt;BR /&gt;"objecttype":"WS",&lt;BR /&gt;"objectname":"Cancel Method / Cancel Request",&lt;BR /&gt;"interface":"CancelAnalysisService",&lt;BR /&gt;"project":"unilims",&lt;BR /&gt;"message":"&amp;lt;ns0:ErrorReport xmlns:ns0=\&lt;A href="http://www.tibco.com/pe/EngineTypes\" target="_blank" rel="noopener"&gt;http://www.tibco.com/pe/EngineTypes\&amp;gt;\n &amp;lt;StackTrace&amp;gt;Job-30001 Error in [Applications/CEP/Processes/In_ADRMAS_A.process/Parse XML]\nA validation occurred while parsing: validation error: unexpected content \"YE1AUSPM\"; expected \"E1BPAD1VL\" or \"E1BPADTEL\" or \"E1BPADFAX\" or \"E1BPADTTX\" or \"E1BPADTLX\" or \"E1BPADSMTP\" or \"E1BPADRML\" or \"E1BPADX400\" or \"E1BPADRFC\" or \"E1BPADPRT\" or \"E1BPADSSF\" or \"E1BPADURI\" or \"E1BPADPAG\" or \"E1BPAD__REM\" or \"E1BPCOMREM\" or \"E1BPADUSE\" ({com.tibco.xml.validation}COMPLEX_E_UNEXPECTED_CONTENT) at /ns:ADRMAS03-4x[1]/CHILDREN[1]/E1ADRMAS[1]/item[1]/CHILDREN[1]/YE1AUSPM[1]\ncom.tibco.xml.validation.exception.UnexpectedElementException: unexpected content \"YE1AUSPM\"; expected \"E1BPAD1VL\" or \"E1BPADTEL\" or \"E1BPADFAX\" or \"E1BPADTTX\" or \"E1BPADTLX\" or \"E1BPADSMTP\" or \"E1BPADRML\" or \"E1BPADX400\" or \"E1BPADRFC\" or \"E1BPADPRT\" or \"E1BPADSSF\" or \"E1BPADURI\" or \"E1BPADPAG\" or \"E1BPAD__REM\" or \"E1BPCOMREM\" or \"E1BPADUSE\"&amp;amp;#xD;\n\tat com.tibco.xml.validation.state.dri",&lt;BR /&gt;"logtype":"Email",&lt;BR /&gt;"transactionid":null,&lt;BR /&gt;"ack_ai":"test.email@sanofi.com",&lt;BR /&gt;"ack_gp":" Order Cancellation Notice, Batch Reference No:"&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;&lt;BR /&gt;search and results some fields are not extracted after message even json&lt;BR /&gt;&lt;BR /&gt;index=test_index source="sandbox_test"&lt;BR /&gt;| table log.*&lt;BR /&gt;&lt;BR /&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;log.datetime log.destsite log.emmsite log.env log.interface log.interfaceid log.objectid log.objectname log.objecttype log.project log.side&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;10/14/2025 19:14:05&lt;/TD&gt;&lt;TD&gt;null&lt;/TD&gt;&lt;TD&gt;CEP&lt;/TD&gt;&lt;TD&gt;dev&lt;/TD&gt;&lt;TD&gt;CancelAnalysisService&lt;/TD&gt;&lt;TD&gt;TI000&lt;/TD&gt;&lt;TD&gt;null&lt;/TD&gt;&lt;TD&gt;Cancel Method / Cancel Request&lt;/TD&gt;&lt;TD&gt;WS&lt;/TD&gt;&lt;TD&gt;utest&lt;/TD&gt;&lt;TD&gt;INB&lt;/TD&gt;&lt;TD&gt;10/14/2025 19:14:05&lt;/TD&gt;&lt;TD&gt;null&lt;/TD&gt;&lt;TD&gt;CEP&lt;/TD&gt;&lt;TD&gt;dev&lt;/TD&gt;&lt;TD&gt;CancelAnalysisService&lt;/TD&gt;&lt;TD&gt;TI000&lt;/TD&gt;&lt;TD&gt;null&lt;/TD&gt;&lt;TD&gt;Cancel Method / Cancel Request&lt;/TD&gt;&lt;TD&gt;WS&lt;/TD&gt;&lt;TD&gt;utest&lt;/TD&gt;&lt;TD&gt;INB&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 14 Oct 2025 12:33:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Some-fields-are-not-extracted-in-json/m-p/754280#M242843</guid>
      <dc:creator>chandrasekhar46</dc:creator>
      <dc:date>2025-10-14T12:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: Some fields are not extracted in json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Some-fields-are-not-extracted-in-json/m-p/754287#M242844</link>
      <description>&lt;P&gt;Please share your event in raw format in a code block using the &amp;lt;/&amp;gt; formatting button.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2025 12:57:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Some-fields-are-not-extracted-in-json/m-p/754287#M242844</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-10-14T12:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Some fields are not extracted in json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Some-fields-are-not-extracted-in-json/m-p/754290#M242845</link>
      <description>Also how long those events can be? There are defaults for auto extraction and those are not so big than you could expect.</description>
      <pubDate>Tue, 14 Oct 2025 13:10:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Some-fields-are-not-extracted-in-json/m-p/754290#M242845</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-10-14T13:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: Some fields are not extracted in json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Some-fields-are-not-extracted-in-json/m-p/754324#M242851</link>
      <description>&lt;P&gt;sorry i was miss some closing blocks here is full event&lt;BR /&gt;&lt;BR /&gt;{&lt;BR /&gt;"log":{&lt;BR /&gt;"emmsite":"CEP",&lt;BR /&gt;"destsite":null,&lt;BR /&gt;"side":"INB",&lt;BR /&gt;"datetime":"10/14/2025 19:14:05",&lt;BR /&gt;"interfaceid":"TI000",&lt;BR /&gt;"env":"dev",&lt;BR /&gt;"objectid":null,&lt;BR /&gt;"objecttype":"WS",&lt;BR /&gt;"objectname":"Cancel Method / Cancel Request",&lt;BR /&gt;"interface":"CancelAnalysisService",&lt;BR /&gt;"project":"test",&lt;BR /&gt;"message":"&amp;lt;ns0:ErrorReport xmlns:ns0=\\&lt;A href="http://www.tibco.com/pe/EngineTypes\" target="_blank"&gt;http://www.tibco.com/pe/EngineTypes\&lt;/A&gt;\&amp;gt;\n &amp;lt;StackTrace&amp;gt;Job-30001 Error in [Applications/CEP/Processes/In_ADRMAS_A.process/Parse XML]\nA validation occurred while parsing: validation error: unexpected content \"YE1AUSPM\"; expected \"E1BPAD1VL\" or \"E1BPADTEL\" or \"E1BPADFAX\" or \"E1BPADTTX\" or \"E1BPADTLX\" or \"E1BPADSMTP\" or \"E1BPADRML\" or \"E1BPADX400\" or \"E1BPADRFC\" or \"E1BPADPRT\" or \"E1BPADSSF\" or \"E1BPADURI\" or \"E1BPADPAG\" or \"E1BPAD__REM\" or \"E1BPCOMREM\" or \"E1BPADUSE\" ({com.tibco.xml.validation}COMPLEX_E_UNEXPECTED_CONTENT) at /ns:ADRMAS03-4x[1]/CHILDREN[1]/E1ADRMAS[1]/item[1]/CHILDREN[1]/YE1AUSPM[1]\ncom.tibco.xml.validation.exception.UnexpectedElementException: unexpected content \"YE1AUSPM\"; expected \"E1BPAD1VL\" or \"E1BPADTEL\" or \"E1BPADFAX\" or \"E1BPADTTX\" or \"E1BPADTLX\" or \"E1BPADSMTP\" or \"E1BPADRML\" or \"E1BPADX400\" or \"E1BPADRFC\" or \"E1BPADPRT\" or \"E1BPADSSF\" or \"E1BPADURI\" or \"E1BPADPAG\" or \"E1BPAD__REM\" or \"E1BPCOMREM\" or \"E1BPADUSE\"&amp;amp;#xD;\n\tat com.tibco.xml.validation.state.dri",&lt;BR /&gt;"logtype":"Email",&lt;BR /&gt;"transactionid":null,&lt;BR /&gt;"ack_ai":"test.emai@testdomain.com",&lt;BR /&gt;"ack_gp":" Batch Reference No:"&lt;BR /&gt;}&lt;BR /&gt;}&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 04:54:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Some-fields-are-not-extracted-in-json/m-p/754324#M242851</guid>
      <dc:creator>chandrasekhar46</dc:creator>
      <dc:date>2025-10-15T04:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: Some fields are not extracted in json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Some-fields-are-not-extracted-in-json/m-p/754329#M242852</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268377"&gt;@chandrasekhar46&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like Splunk’s auto JSON extraction is interrupted by the long/escaped message field. Are you using spath in your search?&lt;/P&gt;&lt;P&gt;Can you try using spath&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| spath
| table log.datetime log.emmsite log.env log.interface log.interfaceid log.objectname log.objecttype log.project log.side log.logtype log.ack_ai log.ack_gp&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dem2.JPG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/40552i16B273EFD4AC4646/image-size/large?v=v2&amp;amp;px=999" role="button" title="dem2.JPG" alt="dem2.JPG" /&gt;&lt;/span&gt;&lt;BR /&gt;or target the specific fields you need&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| spath path=log.logtype
| spath path=log.transactionid
| spath path=log.ack_ai
| spath path=log.ack_gp&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 06:07:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Some-fields-are-not-extracted-in-json/m-p/754329#M242852</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-10-15T06:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: Some fields are not extracted in json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Some-fields-are-not-extracted-in-json/m-p/754334#M242853</link>
      <description>&lt;P&gt;Is this really what your event looks like? I would have expected the namespace to have escaped double quotes, not escaped backslashes?&lt;/P&gt;&lt;P&gt;Please share your raw event is a code block to prevent any undue reformatting of the data.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 07:31:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Some-fields-are-not-extracted-in-json/m-p/754334#M242853</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-10-15T07:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Some fields are not extracted in json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Some-fields-are-not-extracted-in-json/m-p/754382#M242855</link>
      <description>&lt;P&gt;Unless your shared event is butchered by your sharing method, it is NOT a valid JSON object. &amp;nbsp;You can test this with Python's json.tool module&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;python3 -mjson.tool &amp;lt;&amp;lt;&amp;lt;'&amp;lt;your event text&amp;gt;'&lt;/LI-CODE&gt;&lt;P&gt;json.tool will tell you that the &lt;FONT face="courier new,courier"&gt;message&lt;/FONT&gt;&amp;nbsp;is incorrectly quoted as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;suggests: "&lt;SPAN&gt;Invalid \escape: line 14 column 39 (char 304)". &amp;nbsp;When event is not valid, of course Splunk will butcher extraction. (I have also tested with spath - it cannot extract all fields.)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you have sanitized the sample event, make sure you preserve JSON syntax precisely. &amp;nbsp;Share in a code box, not as plain text. &amp;nbsp;Otherwise you need to examine your ingestion, even question your developers about the original content.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Oct 2025 05:20:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Some-fields-are-not-extracted-in-json/m-p/754382#M242855</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2025-10-16T05:20:39Z</dc:date>
    </item>
  </channel>
</rss>

