Getting Data In

Need help a parson json and extract in table format

usharaniallwyn
New Member

Hi ,
I have a json and i want to extract few details in table format .

The json array is like
[features{
elements{
steps{
name
}
}
}
failed:2,
passed:0]

My query:

source="jsondata.json"  index="art" sourcetype="_json"|mvexpand "features{}.elements{}.failed"|rename "features{}.elements{}.failed" as FailedNumber| eval Status=if(FailedNumber=0,"Pass","Fail")|table Status,FailedNumber

Status FailedNumber

Fail 2
Pass 0
Fail 1

second query :

source="jsondata.json" host="CDC2-L-CG72VP2" index="art" sourcetype="_json"|spath output=myfield path="features{}.elements{}.steps{0}.name"|mvexpand myfield |table myfield

myfield↕

the testcase name is "ValidateNetworkBHUtilization"
the testcase is ValidateTrendAmbulatoryCondition
the testcase is TrendHomeHealthCondition

I want ,

Status FailedNumber myfield↕

Fail 2 the testcase name is "ValidateNetworkBHUtilization"
Pass 0 the testcase is ValidateTrendAmbulatoryCondition
Fail 1 the testcase is TrendHomeHealthCondition

Tags (2)
0 Karma

woodcock
Esteemed Legend

Like this:

index="art" source="jsondata.json"  sourcetype="_json"
| multireport
[ mvexpand "features{}.elements{}.failed"|rename "features{}.elements{}.failed" as FailedNumber
| eval Status=if(FailedNumber=0,"Pass","Fail")
|table Status,FailedNumber
|stats count AS _serial]
[ search host="CDC2-L-CG72VP2"
|spath output=myfield path="features{}.elements{}.steps{0}.name"
|mvexpand myfield
|table myfield
| stats count AS _serial]
| selfjoin _serial
0 Karma
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...