Getting Data In

Regarding nested json parsing at index time

snehal
Loves-to-Learn Lots

I want to parse nested json at index time , what will be the props and trandform.I want separate all messages fields in seperate line

{ [-]
   id3614979212324797096956714454
   message{"@t":"2021-05-14T17:19:02.0149138Z","@m":"Upload metrics: \"{ duration = 81.9555, productCode = ct, tenantCode = , validBundle = True, validProductCode = True, validTenantCode = , bundleSize = 9670, successful = True }\"","@i":"0b918ffa","@l":"Information","@lt":"dev","metrics":"{ duration = 81.9555, productCode = ct, tenantCode = , validBundle = True, validProductCode = True, validTenantCode = , bundleSize = 9670, successful = True }","SourceContext":"Atlas.FhirStore.Api.Services.MetricsFhirResourceService","ActionId":"43adca80-545-4b1f-b9dd-d4008f3594b3","ActionName":"Atlas.FhirStore.Api.Controllers.FhirResourceController.UploadBundle (Atlas.FhirStore.Api)","RequestId":"0HM8MV64LIURF","RequestPath":"/api/v1/CT/bundle","SpanId":"|eb806e4b-47275043ec09ec97.2.a9d44dc9_","TraceId":"eb806e4b-47275043ec09ec97","ParentId":"|eb806e4b-47275043ec09ec97.2.","ThreadId":14,"X-Correlation-Id":"0HM8K136VRBAK:00000156","X-Correlation-Name":"IntegrationHubService"}
   timestamp1621012742015

}

Labels (1)
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@snehal 

Can you please share your _raw which has multiple messages value in code format? 

Screenshot 2021-05-15 at 9.32.53 AM.png

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...