Feedback
Got feedback? We want it! Submit your comments and suggestions for our community here.

extracting nested json

MichaelBs
Loves-to-Learn Everything

MichaelBs_1-1715008039869.pngMichaelBs_2-1715008356513.png



I am trying to extract the path as a field to do a lookup with it. I've tried but it doesn't work. I need help extracting that path. There are other paths in the data but need that particular path

0 Karma

marnall
Motivator

Is your data being interpreted by Splunk as JSON? Try expanding the event fields and seeing if it automatically extracts the json fields. If not, you'll have to change the indexing of the event so it is read as a JSON object. Then you can use SPATH or the auto-extracted fields to get the desired values.

0 Karma

MichaelBs
Loves-to-Learn Everything

Spath didn't give the right fields 

0 Karma

youngsuh
Contributor

you have to search and index the json by branch and nodes.  If you need the SPL, let me know.

0 Karma

MichaelBs
Loves-to-Learn Everything

I need the SPL

0 Karma

MichaelBs
Loves-to-Learn Everything
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What has many keys but can’t unlock a door?

July 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunk Asynchronous Forwarding Explained

Splunk asynchronous forwarding is often misunderstood as simply setting autoLBVolume. That is not quite right. ...

55 Days to Go: Secure Your Seat at Splunk University in Denver

Your .conf26 Experience Starts Before Opening Keynote  If Denver is known for its mile-high elevation, Splunk ...