Splunk Enterprise

parsing out value from multi value field

dtakacssplunk
Explorer

I have data in the following form:

field A,    field B(this is an array)

a              {"k":1}

                {"k":2}

                {"k":3}

b              {"k":1}

                {"k":1}

                {"k":1}

field B is an array, I want to produce table like this

field A, sumB

a     6

b    3

what is the way to extract the values and add them up?

my thinking was to do 

| eval value=spath(fieldB, "k") 

and I was expecting values to have array 1,2,3 and 1,1,1 but they did not

Labels (1)
0 Karma

thambisetty
Super Champion

| rex field=fieldB "k\":(?<fieldb_val>\d+)"

| stats sum(fieldb_val) by fieldA

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...