This is the basic case:
I have an event
2021-12-28T06:24:17.567|SEARCHING|{"field1":"value1","field2":5,"field3":"la la la"}
My search
index="redact" SEARCHING | spath path="field3"
Splunk is separating the values, but field3 column is empty for all events.
Can anyone please assist?
Try this.
index="redact" SEARCHING | rex field=_raw "(?<_raw>\{.*\})" | spath | table field3
My Sample Search :
| makeresults | eval _raw="2021-12-28T06:24:17.567|SEARCHING|{\"field1\":\"value1\",\"field2\":5,\"field3\":\"la la la\"}" | rex field=_raw "(?<_raw>\{.*\})" | spath | table field3
Thanks
KV
▄︻̷̿┻̿═━一 😉
If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.
This worked perfect. Thank you for your help!
I had to change the "<" and ">" to entities and it worked amazing!
| rex field=_raw "(?<_raw>\{.*\})" |
Try this.
index="redact" SEARCHING | rex field=_raw "(?<_raw>\{.*\})" | spath | table field3
My Sample Search :
| makeresults | eval _raw="2021-12-28T06:24:17.567|SEARCHING|{\"field1\":\"value1\",\"field2\":5,\"field3\":\"la la la\"}" | rex field=_raw "(?<_raw>\{.*\})" | spath | table field3
Thanks
KV
▄︻̷̿┻̿═━一 😉
If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.
This worked perfect. Thank you for your help!
I had to change the "<" and ">" to entities and it worked amazing!
| rex field=_raw "(?<_raw>\{.*\})" |