Getting Data In

How to convert JSON Keys and values as columns in splunk

sdaruna
Explorer

Hi,

I want to flatten json data to columns for my report purpose. I might not be explaining my requirement properly, here is what my data and result has to be.

Input:

{
"name" : "srini",
"value" {
"1": "val1",
"2" : "val2",
"3" : "val3"
}
}

Output:

name, name.key, name.value
------------------------------------------
srini      1         val1
srini      2         val2
srini      3         val3
Tags (1)
0 Karma
1 Solution

javiergn
Super Champion

I think your JSON is wrong and there's a colon missing after value.
In any case, see if the below helps:

| makeresults
| eval json = "
{
   \"name\" : \"srini\",
   \"value\": {
      \"1\": \"val1\",
      \"2\" : \"val2\",
      \"3\" : \"val3\"
   }
}
"
| spath input=json
| fields - json
| untable name key value
| rex field=key "(?<key>\d+)"
| rename key AS name.key, value AS name.value

Output (see picture below):

alt text

View solution in original post

0 Karma

javiergn
Super Champion

I think your JSON is wrong and there's a colon missing after value.
In any case, see if the below helps:

| makeresults
| eval json = "
{
   \"name\" : \"srini\",
   \"value\": {
      \"1\": \"val1\",
      \"2\" : \"val2\",
      \"3\" : \"val3\"
   }
}
"
| spath input=json
| fields - json
| untable name key value
| rex field=key "(?<key>\d+)"
| rename key AS name.key, value AS name.value

Output (see picture below):

alt text

0 Karma

jkat54
SplunkTrust
SplunkTrust
0 Karma

sdaruna
Explorer

I have so many key value pairs under "value" field. So it is not possible to specify each and every key of "value" field.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...