Hi,
I'm using the PRTG app to get logs from this monitoring tool and build clean reports about our servers health.
The API is returning a JSON and the automatic field extraction gets fields like sensors{}.sensor.
How could I build a query referencing to this fields? If I try something like this fails:
index=prtg "sensors{}.sensor"=Ping
Thanks
I also tried use eval and filter by the new result without success
It looks like sensors{}.sensor is a multi-value field - try extracting the collection (spath) and separate each element into different events (mvexpand), then extract the fields you are interested in (spath again).
Thanks
I didn't know spath command, but after try it I have the same problem with the new field...
Any idea?
Thanks
index=prtg
| spath output=sensors path=sensors{}
| mvexpand sensors
| search Ping
| spath input=sensors
Try with single quotes not double
index=prtg 'sensors{}.sensor'=Ping