Security

how do i access a field that is not listed?

dgonzales999
New Member

How do I access "processing_time" from the data below. I want to get the average time. It is not listed as a field.
{"@type":"log:LogIncomingRequestEvent","level":"INFO","when":"2014-05-29 16:04:06,459","method":"LogFilter.logIncomingRequest#156","thread":"http-bio-8087-exec-4","init_tid":"b0507da3-6687-4028-8fe2-8c98c92b783d","request":{ "@type":"log:IncomingRequest", "client_ip":"pqal.corp.net","http_method":"POST","url":"/mms/v1/transfers","user_agent":"Apache-HttpClient/4.3.2 (java 1.5)","processing_time":137},"msg":"OK"}

Tags (1)
0 Karma

stefandagerman
Path Finder

Can you not set KV_MODE=JSON (your event looks like it is valid JSON) in props.conf for the sourcetype and let Splunk do the work for you?
props.conf docs

somesoni2
Revered Legend

It is a valid json, validated from http://jsonlint.com/. Once you import the data with KV_MODE=JSON, you should be able to see fields like 'request.processing_time' and then you can use 'stats' command to get the average.

0 Karma

grijhwani
Motivator

Easiest way is to use the field extractor tool.

Generate a search that contains it then select the drop-down next to one of the presented records, and select "field extractor".

http://docs.splunk.com/Documentation/Splunk/6.1.1/Knowledge/ExtractfieldsinteractivelywithIFX

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...