Getting Data In

How do you parse JSON from a specific field?

joshimeister
Loves-to-Learn Lots

I tried search in the community support section for something similar to my issue.

I am trying to parse a specific field which is actually in JSON format. Is there a way to parse out anything within the message section. Below is a sample.

Field name is errorMessage_Field and contains the info below:

{"level":"error","schema":{"loadingURI":"#","pointer":"/definitions/blah"},"instance":{"pointer":"/blah"},"domain":"validation","keyword":"required","message":"object has missing required properties ([\"presosBlahID\"])","required":["presosBlahID"],"missing":["presosBlahID"]}

Using the JSON entry above, im trying to show a table that just shows:
Count | Detailed Error Message
3 | Object has missing required properties: presosBlahID

I realize that using spath is the way to do it but i have not been successful.

index=index_name sourcetype="sourcetype_name errorMessage_Field="errorMessage earliest=-15h
| bucket span=1m _time
| stats count by errorMessage_Field
| fields count errorMessage_Field
| rename count AS "Error Count"
| rename errorMessage_Field AS "Detailed Error Message"

Any assistance is greatly appreciated.

Thanks!

0 Karma

marycordova
SplunkTrust
SplunkTrust

I've has some issues with JSON where most but not all of it gets parsed. For those I've written a regex and dropped it into props.conf for that particular sourcetype or source.

in search to test before adding to .props:

index=index_name sourcetype=sourcetype_name errorMessage_Field=errorMessage earliest=-15h
| bucket span=1m _time
| stats count AS "Error Count" by errorMessage_Field
| rex field=errorMessage_Field "regex here is getting messed up see below"
| eval "Detailed Error Message"=mvzip('message','detail')
| table "Error Count" "Detailed Error Message"

\"message\":\"(?< message>[\w\s]+)\s(\ [\\"(?< detail>[^\]+)

there is an artificial space added before "message", the 2nd "[", and "detail" since this editor kept trying to interpret/mess the regex up

@marycordova
0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...