Getting Data In

Need help on breaking my json data to several events

robertbumanglag
Engager

I'm really stucked right now on my configuration for my json data below.

robertbumanglag_0-1608719516683.png

 

I'm currently building a data collector app in Splunk Add-on Builder. Here's the current configuration

robertbumanglag_1-1608719590840.png

 

My goal is to break the Integration_Business_Process_Events_group sub values into another event but should retain parent event details. So instead of having 1 event, I should have 6 events.

 

Hope for your answers. I already look into to the other similar problem like this by I'm getting more confuse.

 

Thanks everyone!

0 Karma
1 Solution

to4kawa
Ultra Champion

props.conf can't extract what you want.

try following:

index=your_index sourcetype=your_sourcetype
| spath Integration_Business_Process_Events_group{} output=IBPEg
| mvexpand IBPEg
| spath
| spath input=IBPEg
| fields - Integration_Business_Process_Events_group* IBPEg _raw
| table *

 

View solution in original post

to4kawa
Ultra Champion

props.conf can't extract what you want.

try following:

index=your_index sourcetype=your_sourcetype
| spath Integration_Business_Process_Events_group{} output=IBPEg
| mvexpand IBPEg
| spath
| spath input=IBPEg
| fields - Integration_Business_Process_Events_group* IBPEg _raw
| table *

 

robertbumanglag
Engager

Hi! Thanks, this helped.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...