Getting Data In

How to extract json fields?

karthi2809
Builder

This is my Logs

{ [-]
line: 2019-03-20T11:33:06.942Z info: Response: ServiceName: Pharmacy.findPharmacy; URI: /findpharmacy/; TranasactionStartTime: 1553081580; TransactionEndTime: 1553081586; StatusCode: 0000; refId: 50ab9d41ab2ee8abc0664f3f17a0df57;

source: stdout
tag: pharmacyv3caremark.2.6jus1ayt1c9ejdnxd1qi356lx;30997f60e91e;sit1-dtr.anthem.com/sit/pharmacyv3caremark:release-37@sha256:e1eb70168332a5f9ac9f1cdc5da83953087f507d254779a91cbc361b0e7ce872

}

I need extract ServiceName TranasactionStartTime TransactionEndTime StatusCode refId

0 Karma

nickhills
Ultra Champion

That's not valid json, but i wonder if that's because some characters have been stripped.
When you post raw text you should use the code formatter tool which looks like 101010

Can you confirm if this data has been indexed as _json (it looks like maybe it has) in which case the fields may have been extracted already.

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...