Getting Data In

Is there a way to use kv_mode=json and eliminate one level in spath?

dominiquevocat
SplunkTrust
SplunkTrust

Is there a way to use kv_mode=json and remove levels of nesting during indexing or later?

Example: we jave some json (jboss) that looks like this:

{
    "outcome" : "success",
    "result" : {
        "name" : "32740@chhs-ssys060",
        "vm-name" : "Java HotSpot(TM) 64-Bit Server VM",
        "vm-vendor" : "Sun Microsystems Inc.",
        "vm-version" : "20.60-b01",
        "spec-name" : "Java Virtual Machine Specification",
        "spec-vendor" : "Sun Microsystems Inc.",
        "spec-version" : "1.0",

resulting in fields that are named result.name, result.vm-version etc.
My goal is to remove the top level node "result" so the fields names are "cleaner" i.e. name, vm-version.

It is a somewhat narrow usecase because all results i want are in the node "result". If it is not too taxing one could probably do a eval on any result.* field and rename it during search time to *? what would be the best way to do so? Is there a easy option for the spath or kv_mode=json that i overlooked?

0 Karma
1 Solution

somesoni2
Revered Legend

The simplest solution would be to configure field alias on your search head to rename all result.FieldName to just FieldName. A sample props.conf for the same would be like this

props.conf on Search Head

[Your sourcetype]
...other configurations...
FIELDALIAS-result = result.* as *

View solution in original post

somesoni2
Revered Legend

The simplest solution would be to configure field alias on your search head to rename all result.FieldName to just FieldName. A sample props.conf for the same would be like this

props.conf on Search Head

[Your sourcetype]
...other configurations...
FIELDALIAS-result = result.* as *

dominiquevocat
SplunkTrust
SplunkTrust

looks good, think its no performance penalty.
Thanks

0 Karma
Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...