Getting Data In

Display parts of an event as JSON

mrg_linus
Engager

alt text

What I want to do is display the content of the message.model. However when I attempt to do this with things as

MYSEARCH | spath output=myfield path="message.model" | table myfield
the output is not visualized as JSON (but as text with no spaces, indentation or linebreaks).

I want the same visualization as in the attached image, but ONLY the message.model.

How do I achieve this?

0 Karma

mrg_linus
Engager

Sadly Im not allowed to upload pictures. Therefore Im using multiple answers in order to do so. Probably something you might want to look into.alt text

0 Karma

mrg_linus
Engager

I'm the slowest person in the world 😛

that being said this is the finished result using your xml code in my dashboard

alt text

0 Karma

niketn
Legend

@mrg_linus, the above view is only available with visualization selected as Events. Even in your screenshot you would notice a link to toggle the event view between Show syntax higlighted and Show as raw text. You can use the same in Event visualization but with your JSON subset as a new field.

Following is sample Simple XML with eventview. Replace your actual search to try out:

      <row>
        <panel>
          <event>
            <search>
              <query>MYSEARCH 
| spath output=myfield path="message.model" 
| table myfield</query>
              <earliest>0</earliest>
              <latest></latest>
              <sampleRatio>1</sampleRatio>
            </search>
            <option name="count">20</option>
            <option name="list.drilldown">none</option>
            <option name="list.wrap">1</option>
            <option name="maxLines">5</option>
            <option name="raw.drilldown">full</option>
            <option name="refresh.display">progressbar</option>
            <option name="rowNumbers">0</option>
            <option name="table.drilldown">all</option>
            <option name="table.sortDirection">asc</option>
            <option name="table.wrap">1</option>
            <option name="type">list</option>
          </event>
        </panel>
      </row>
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

mrg_linus
Engager

Poke. Find the result of your suggestion below.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...