Getting Data In

Trying to parse my Json into a table

dperry
Communicator

this is the format:

{
"epoch": "1485892851.94944",
"id": "3952418",
"name": "WMI Performance Adapter",
"new_attrs": "{\"DisplayName\":\"WMI Performance Adapter\",\"ServiceName\":\"wmiApSrv\",\"enabled\":\"Manual\",\"state\":\"Running\",\"User\":\"localSystem\"}",
"new_scan_id": "513186",
"node_environment_id": "2",
"node_id": "153",
"node_name": "servername",
"node_primary_node_group_id": "68",
"old_attrs": "{\"DisplayName\":\"WMI Performance Adapter\",\"ServiceName\":\"wmiApSrv\",\"enabled\":\"Manual\",\"state\":\"Stopped\",\"User\":\"localSystem\"}",
"old_scan_id": "513150",
"path": "{services,windows}",
"status": "modified",
"type": "services",
"updated_at": "2017-01-31 20:00:51.949442"
}

trying to use the spath

Tags (3)
0 Karma
1 Solution

rsennett_splunk
Splunk Employee
Splunk Employee

I believe this is what you are looking for:
I selected one field from new_attr and old_attr because it is the only one that differs. Otherwise you can't see what's happening.

 index=blah sourcetype=blah 
| spath input=new_attrs 
|rename state AS newState
|spath input=old_attrs
|rename state AS oldState
|table newState oldState

But you would simply rename the ones you wanted. ie rename state as newState, DisplayName AS newDisplay, ServiceName AS Fred

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!

View solution in original post

0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

I believe this is what you are looking for:
I selected one field from new_attr and old_attr because it is the only one that differs. Otherwise you can't see what's happening.

 index=blah sourcetype=blah 
| spath input=new_attrs 
|rename state AS newState
|spath input=old_attrs
|rename state AS oldState
|table newState oldState

But you would simply rename the ones you wanted. ie rename state as newState, DisplayName AS newDisplay, ServiceName AS Fred

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma

dperry
Communicator

Thanks Producer! This is along the lines of what I was visioning.

0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

woohoo! Excellent. 🙂

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...