Feedback
Got feedback? We want it! Submit your comments and suggestions for our community here.

extracting nested json

MichaelBs
Loves-to-Learn Everything

MichaelBs_1-1715008039869.pngMichaelBs_2-1715008356513.png



I am trying to extract the path as a field to do a lookup with it. I've tried but it doesn't work. I need help extracting that path. There are other paths in the data but need that particular path

0 Karma

marnall
Motivator

Is your data being interpreted by Splunk as JSON? Try expanding the event fields and seeing if it automatically extracts the json fields. If not, you'll have to change the indexing of the event so it is read as a JSON object. Then you can use SPATH or the auto-extracted fields to get the desired values.

0 Karma

MichaelBs
Loves-to-Learn Everything

Spath didn't give the right fields 

0 Karma

youngsuh
Contributor

you have to search and index the json by branch and nodes.  If you need the SPL, let me know.

0 Karma

MichaelBs
Loves-to-Learn Everything

I need the SPL

0 Karma

MichaelBs
Loves-to-Learn Everything
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...