Splunk Enterprise

parsing out value from multi value field

dtakacssplunk
Explorer

I have data in the following form:

field A,    field B(this is an array)

a              {"k":1}

                {"k":2}

                {"k":3}

b              {"k":1}

                {"k":1}

                {"k":1}

field B is an array, I want to produce table like this

field A, sumB

a     6

b    3

what is the way to extract the values and add them up?

my thinking was to do 

| eval value=spath(fieldB, "k") 

and I was expecting values to have array 1,2,3 and 1,1,1 but they did not

Labels (1)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

| rex field=fieldB "k\":(?<fieldb_val>\d+)"

| stats sum(fieldb_val) by fieldA

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...