Getting Data In

Not able to parse json with spath ,something wrong but not json

ekmek4
Explorer

Hi,

I need to ingest some logs into splunk, so file&dirs data input its my choice.

Also new index was created , _json as sourcetype. Now im trying to use spath in search to parse JSON data with multifields and no luck yet. Just checked my json file - valid json.

ekmek4_0-1740504817781.png

Here we have some parsed json, but i want to get email, first_name,last_name from properties.attributes to be able parse or filter by any of this fields in future

 

Appreciate any help.

Small source file:

https://paste2.org/OsEXkgbJ

 

Here is what i tried :

index=ep_log event=created | spath properties.attributes

index=erp_log event=created | spath properties and so on

Labels (1)
0 Karma
1 Solution

ekmek4
Explorer

index=ep_log event=created | spath path=properties | mvexpand properties | spath input=properties

This query automatically expand fields with every attribute key. 

View solution in original post

0 Karma

ekmek4
Explorer

index=ep_log event=created | spath path=properties | mvexpand properties | spath input=properties

This query automatically expand fields with every attribute key. 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

| spath properties
| spath input=properties attributes

ekmek4
Explorer

Now i have a new field "attributes"

attributes: 

 {"email": "gacilia@gmail.com", "clients": {"ERP Frontend": "GEgzvJrIJxxHNS9FVdSvUej5wyrBgd2sSHH7RLuE", "Frontend CRM": "ILrkYrSCSsKgdgxBRv0COxKLaOzKufXogzWEAoh8"}, "is_active": false, "last_name": "Gac", "legacy_id": "66f510fea8f5e1ff130f5fa0", "first_name": "Ilia", "start_date": null, "is_team_supervisor": true, "two_factor_auth_enabled": false}

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Does this give you what you want?

| spath properties
| spath input=properties attributes
| spath input=attributes
0 Karma

ekmek4
Explorer
| spath path=properties | mvexpand properties | spath input=properties

 

this works fine for me. Thank you!!

0 Karma
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcment

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...