Getting Data In

How do you parse JSON from a specific field?

joshimeister
Loves-to-Learn Lots

I tried search in the community support section for something similar to my issue.

I am trying to parse a specific field which is actually in JSON format. Is there a way to parse out anything within the message section. Below is a sample.

Field name is errorMessage_Field and contains the info below:

{"level":"error","schema":{"loadingURI":"#","pointer":"/definitions/blah"},"instance":{"pointer":"/blah"},"domain":"validation","keyword":"required","message":"object has missing required properties ([\"presosBlahID\"])","required":["presosBlahID"],"missing":["presosBlahID"]}

Using the JSON entry above, im trying to show a table that just shows:
Count | Detailed Error Message
3 | Object has missing required properties: presosBlahID

I realize that using spath is the way to do it but i have not been successful.

index=index_name sourcetype="sourcetype_name errorMessage_Field="errorMessage earliest=-15h
| bucket span=1m _time
| stats count by errorMessage_Field
| fields count errorMessage_Field
| rename count AS "Error Count"
| rename errorMessage_Field AS "Detailed Error Message"

Any assistance is greatly appreciated.

Thanks!

0 Karma

marycordova
SplunkTrust
SplunkTrust

I've has some issues with JSON where most but not all of it gets parsed. For those I've written a regex and dropped it into props.conf for that particular sourcetype or source.

in search to test before adding to .props:

index=index_name sourcetype=sourcetype_name errorMessage_Field=errorMessage earliest=-15h
| bucket span=1m _time
| stats count AS "Error Count" by errorMessage_Field
| rex field=errorMessage_Field "regex here is getting messed up see below"
| eval "Detailed Error Message"=mvzip('message','detail')
| table "Error Count" "Detailed Error Message"

\"message\":\"(?< message>[\w\s]+)\s(\ [\\"(?< detail>[^\]+)

there is an artificial space added before "message", the 2nd "[", and "detail" since this editor kept trying to interpret/mess the regex up

@marycordova
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...