Getting Data In

moving "spath" from query to config file

splunk_worker
Path Finder

Hi All
I want to move the spath from search query to the auto extraction configuration ie in props.conf and transforms.conf. Is this possible?

index=myindex | rex max_match=0 "(?{[^}]+})" | mvexpand json_field |spath input=json_field

spath breaks KV from complex JSON too. Hence I want use spath, but in configuration files instead of search query.

cpride_splunk
Splunk Employee
Splunk Employee

Given the fact that spath is happening after mvexpand and a rex -- I'm not sure it helps.

However if you were trying to basically have a single automatically extracted path command:

search foo=* | spath input=foo output=bar path=a.b

That is equivalent to (Spath Eval Function😞

search foo=* | eval bar=spath(foo, "a.b")

And you can embed that eval as a calculated field (Define Calculated Fields) to make it automatically extracted.

GauravSplunxter
Explorer

I embedded in props.conf and not getting the results.
EVAL-bar = spath(foo, "a.b")
What am I doing wrong?

0 Karma

camillak
Path Finder

Did you set the stanza correctly? eg: [source::your_source]

Also the parse won't show up in an Events search, need to table or similar.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...