Monitoring Splunk

How to do loop on array?

bhanusaketi
Loves-to-Learn

How to loop the array values after split with delimiter 

| eval json="{"key1":"key1value","key2":"key2value","key3":"key3value","key4":"key4Value" }"

| eval keyNames ="key1,key2,key3,key4" // key names can add or remove based on search string the requirement 

 | eval keys=split(keyNames ,";")

How to loop these keys and perform some operation. 

I have tired with some MV commands but no luck.

Example: 

| eval count = mvcount(keys)

| streamstats count as counter

| eval jsonKey= mvindex(keys,count) | eval keyValue = json_extract(json, jsonKey)

I am not sure how to achieve this use case, can some one please help me on it.

 

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

SPL is not a procedural language so there isn't a "loop through" construct per se. However, it depends on what it is you are trying to achieve as to whether there is another way to do it. For example, if you want to simply extract the key-value pairs from the json string use spath

| eval json="{\"key1\":\"key1value\",\"key2\":\"key2value\",\"key3\":\"key3value\",\"key4\":\"key4Value\" }"
| spath input=json
0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...