Getting Data In

How do you parse JSON from a specific field?

joshimeister
Loves-to-Learn Lots

I tried search in the community support section for something similar to my issue.

I am trying to parse a specific field which is actually in JSON format. Is there a way to parse out anything within the message section. Below is a sample.

Field name is errorMessage_Field and contains the info below:

{"level":"error","schema":{"loadingURI":"#","pointer":"/definitions/blah"},"instance":{"pointer":"/blah"},"domain":"validation","keyword":"required","message":"object has missing required properties ([\"presosBlahID\"])","required":["presosBlahID"],"missing":["presosBlahID"]}

Using the JSON entry above, im trying to show a table that just shows:
Count | Detailed Error Message
3 | Object has missing required properties: presosBlahID

I realize that using spath is the way to do it but i have not been successful.

index=index_name sourcetype="sourcetype_name errorMessage_Field="errorMessage earliest=-15h
| bucket span=1m _time
| stats count by errorMessage_Field
| fields count errorMessage_Field
| rename count AS "Error Count"
| rename errorMessage_Field AS "Detailed Error Message"

Any assistance is greatly appreciated.

Thanks!

0 Karma

marycordova
SplunkTrust
SplunkTrust

I've has some issues with JSON where most but not all of it gets parsed. For those I've written a regex and dropped it into props.conf for that particular sourcetype or source.

in search to test before adding to .props:

index=index_name sourcetype=sourcetype_name errorMessage_Field=errorMessage earliest=-15h
| bucket span=1m _time
| stats count AS "Error Count" by errorMessage_Field
| rex field=errorMessage_Field "regex here is getting messed up see below"
| eval "Detailed Error Message"=mvzip('message','detail')
| table "Error Count" "Detailed Error Message"

\"message\":\"(?< message>[\w\s]+)\s(\ [\\"(?< detail>[^\]+)

there is an artificial space added before "message", the 2nd "[", and "detail" since this editor kept trying to interpret/mess the regex up

@marycordova
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...