Getting Data In

Help with Parsing multivalue fields

topher1
Engager

Can anyone help me with extracting/parsing the multivalue fields  in sample event below using props and transforms conf.

{\"ts\":1660880406.308522,\"uid\":\"CKFf5h2a9xFmkGFeFj\",\"id.orig_h\":\"10.10.10.16\",\"id.orig_p\":64179,\"id.resp_h\":\"8.8.4.4\",\"id.resp_p\":53,\"proto\":\"udp\",\"trans_id\":50808,\"rtt\":0.12951111793518067,\"query\":\"discord.com\",\"qclass\":1,\"qclass_name\":\"C_INTERNET\",\"qtype\":1,\"qtype_name\":\"A\",\"rcode\":0,\"rcode_name\":\"NOERROR\",\"AA\":false,\"TC\":false,\"RD\":true,\"RA\":true,\"Z\":0,\"answers\":[\"162.159.135.232\",\"162.159.138.232\",\"162.159.137.232\",\"162.159.136.232\",\"162.159.128.233\"],\"TTLs\":[300.0,300.0,300.0,300.0,300.0]

 

Labels (2)
0 Karma
1 Solution

topher1
Engager

Well, I actually figured it out using the split command....after I posted for help.

>>Transforms.conf
[multivalue_regex_field_extraction]
REGEX = \\"([\w|.]+)\\":\[\\?"?([^\]]+?)\\?"?\]
FORMAT = $1::$2
CLEAN_KEYS = false

>>>Props.conf
REPORT-regex_field_extraction = multivalue_regex_field_extraction
EVAL-answers = split(answers,"\\\",\\\"")
EVAL-TTLs = split(TTLs,",")

Works great!

View solution in original post

Tags (1)

richgalloway
SplunkTrust
SplunkTrust

What have you tried so far?  Are you looking fo rindex-time extractions or search-time extractions?

---
If this reply helps you, Karma would be appreciated.
0 Karma

topher1
Engager

Well, I actually figured it out using the split command....after I posted for help.

>>Transforms.conf
[multivalue_regex_field_extraction]
REGEX = \\"([\w|.]+)\\":\[\\?"?([^\]]+?)\\?"?\]
FORMAT = $1::$2
CLEAN_KEYS = false

>>>Props.conf
REPORT-regex_field_extraction = multivalue_regex_field_extraction
EVAL-answers = split(answers,"\\\",\\\"")
EVAL-TTLs = split(TTLs,",")

Works great!

Tags (1)
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...