Getting Data In

Need help on breaking my json data to several events

robertbumanglag
Engager

I'm really stucked right now on my configuration for my json data below.

robertbumanglag_0-1608719516683.png

 

I'm currently building a data collector app in Splunk Add-on Builder. Here's the current configuration

robertbumanglag_1-1608719590840.png

 

My goal is to break the Integration_Business_Process_Events_group sub values into another event but should retain parent event details. So instead of having 1 event, I should have 6 events.

 

Hope for your answers. I already look into to the other similar problem like this by I'm getting more confuse.

 

Thanks everyone!

0 Karma
1 Solution

to4kawa
Ultra Champion

props.conf can't extract what you want.

try following:

index=your_index sourcetype=your_sourcetype
| spath Integration_Business_Process_Events_group{} output=IBPEg
| mvexpand IBPEg
| spath
| spath input=IBPEg
| fields - Integration_Business_Process_Events_group* IBPEg _raw
| table *

 

View solution in original post

to4kawa
Ultra Champion

props.conf can't extract what you want.

try following:

index=your_index sourcetype=your_sourcetype
| spath Integration_Business_Process_Events_group{} output=IBPEg
| mvexpand IBPEg
| spath
| spath input=IBPEg
| fields - Integration_Business_Process_Events_group* IBPEg _raw
| table *

 

robertbumanglag
Engager

Hi! Thanks, this helped.

0 Karma
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...