<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to extract a JSON object which is in double quotes? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-a-JSON-object-which-is-in-double-quotes/m-p/242228#M72057</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;here you go. The important bit is the line with the rex command. The rest of it I just used to simulate the event and present the result.&lt;/P&gt;

&lt;P&gt;|stats count|eval count="2016-01-20 17:40:38,076 INFO &lt;A href="https://community.splunk.com/ajp-/10.32.20.21:8309-27" target="_blank"&gt;org.apache.log4j.Logger&lt;/A&gt; transaction_id=\"1234565\" &lt;BR /&gt;
    Json_object = \"{ &lt;BR /&gt;
    \"requestId\": \"123\", &lt;BR /&gt;
    \"partnerId\": \"asd\", &lt;BR /&gt;
    \"date\":\"01/01/2015 14:00:00\" &lt;BR /&gt;
    }\"&lt;BR /&gt;
    tmepId =\"123\""|&lt;/P&gt;

&lt;P&gt;rex field=count "(?s)\"(?{.*})\""&lt;/P&gt;

&lt;P&gt;|table count myjson|spath input=myjson&lt;/P&gt;

&lt;P&gt;BR&lt;BR /&gt;
Oliver&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 08:35:36 GMT</pubDate>
    <dc:creator>ohoppe</dc:creator>
    <dc:date>2020-09-29T08:35:36Z</dc:date>
    <item>
      <title>How to extract a JSON object which is in double quotes?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-a-JSON-object-which-is-in-double-quotes/m-p/242227#M72056</link>
      <description>&lt;P&gt;Hi, I've a JSON object logged into splunk in double quotes. What to do to extract the JSON object using spath. How do I ignore the double quotes before doing the spath.&lt;/P&gt;

&lt;P&gt;2016-01-20 17:40:38,076 INFO  &lt;A href="https://community.splunk.com/ajp-/10.32.20.21:8309-27" target="_blank"&gt;org.apache.log4j.Logger&lt;/A&gt; transaction_id="1234565" &lt;BR /&gt;
 Json_object =  "{&lt;BR /&gt;&lt;BR /&gt;
 "requestId": "123",&lt;BR /&gt;&lt;BR /&gt;
    "partnerId": "asd",&lt;BR /&gt;&lt;BR /&gt;
   "date":"01/01/2015 14:00:00"&lt;BR /&gt;&lt;BR /&gt;
}"&lt;BR /&gt;
tmepId ="123"&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:30:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-a-JSON-object-which-is-in-double-quotes/m-p/242227#M72056</guid>
      <dc:creator>Kukkadapu</dc:creator>
      <dc:date>2020-09-29T08:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract a JSON object which is in double quotes?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-a-JSON-object-which-is-in-double-quotes/m-p/242228#M72057</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;here you go. The important bit is the line with the rex command. The rest of it I just used to simulate the event and present the result.&lt;/P&gt;

&lt;P&gt;|stats count|eval count="2016-01-20 17:40:38,076 INFO &lt;A href="https://community.splunk.com/ajp-/10.32.20.21:8309-27" target="_blank"&gt;org.apache.log4j.Logger&lt;/A&gt; transaction_id=\"1234565\" &lt;BR /&gt;
    Json_object = \"{ &lt;BR /&gt;
    \"requestId\": \"123\", &lt;BR /&gt;
    \"partnerId\": \"asd\", &lt;BR /&gt;
    \"date\":\"01/01/2015 14:00:00\" &lt;BR /&gt;
    }\"&lt;BR /&gt;
    tmepId =\"123\""|&lt;/P&gt;

&lt;P&gt;rex field=count "(?s)\"(?{.*})\""&lt;/P&gt;

&lt;P&gt;|table count myjson|spath input=myjson&lt;/P&gt;

&lt;P&gt;BR&lt;BR /&gt;
Oliver&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:35:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-a-JSON-object-which-is-in-double-quotes/m-p/242228#M72057</guid>
      <dc:creator>ohoppe</dc:creator>
      <dc:date>2020-09-29T08:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract a JSON object which is in double quotes?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-a-JSON-object-which-is-in-double-quotes/m-p/242229#M72058</link>
      <description>&lt;P&gt;Thanks Oliver. That worked:)&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2016 16:26:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-a-JSON-object-which-is-in-double-quotes/m-p/242229#M72058</guid>
      <dc:creator>Kukkadapu</dc:creator>
      <dc:date>2016-01-27T16:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract a JSON object which is in double quotes?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-a-JSON-object-which-is-in-double-quotes/m-p/242230#M72059</link>
      <description>&lt;P&gt;Very Welcome. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2016 16:30:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-a-JSON-object-which-is-in-double-quotes/m-p/242230#M72059</guid>
      <dc:creator>ohoppe</dc:creator>
      <dc:date>2016-01-27T16:30:43Z</dc:date>
    </item>
  </channel>
</rss>

