Getting Data In

Display parts of an event as JSON

mrg_linus
Engager

alt text

What I want to do is display the content of the message.model. However when I attempt to do this with things as

MYSEARCH | spath output=myfield path="message.model" | table myfield
the output is not visualized as JSON (but as text with no spaces, indentation or linebreaks).

I want the same visualization as in the attached image, but ONLY the message.model.

How do I achieve this?

0 Karma

mrg_linus
Engager

Sadly Im not allowed to upload pictures. Therefore Im using multiple answers in order to do so. Probably something you might want to look into.alt text

0 Karma

mrg_linus
Engager

I'm the slowest person in the world 😛

that being said this is the finished result using your xml code in my dashboard

alt text

0 Karma

niketn
Legend

@mrg_linus, the above view is only available with visualization selected as Events. Even in your screenshot you would notice a link to toggle the event view between Show syntax higlighted and Show as raw text. You can use the same in Event visualization but with your JSON subset as a new field.

Following is sample Simple XML with eventview. Replace your actual search to try out:

      <row>
        <panel>
          <event>
            <search>
              <query>MYSEARCH 
| spath output=myfield path="message.model" 
| table myfield</query>
              <earliest>0</earliest>
              <latest></latest>
              <sampleRatio>1</sampleRatio>
            </search>
            <option name="count">20</option>
            <option name="list.drilldown">none</option>
            <option name="list.wrap">1</option>
            <option name="maxLines">5</option>
            <option name="raw.drilldown">full</option>
            <option name="refresh.display">progressbar</option>
            <option name="rowNumbers">0</option>
            <option name="table.drilldown">all</option>
            <option name="table.sortDirection">asc</option>
            <option name="table.wrap">1</option>
            <option name="type">list</option>
          </event>
        </panel>
      </row>
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

mrg_linus
Engager

Poke. Find the result of your suggestion below.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...