Splunk Search

Convert stats to JSON

wpb162
Explorer

I have a user who wants to send a table resulting from | stats values() to a summary index via the collect command, but all of the logs in this summary index need to be in json format. By default, collect just separates the field-value pairs by commas. How would we format these in json before or after the collect command sends them to the summary index?

Labels (2)
0 Karma

woodcock
Esteemed Legend

Like this:

index=_*
| stats count values(sourcetype) AS sourcetype BY index
| tojson
| eval _time = now()
| table _raw
| collect index=main source="test" addtime=true testmode=true

wpb162
Explorer

I appreciate your answer, and I hope to be able to use it very soon. However, we currently are running Splunk version 8.0.10, so I don't believe the tojson command is available to us.  If there is another (probably more complicated) way to do that with our current version, that would be fantastic. Otherwise, I expect we will have to wait until we upgrade.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

8.0 line has been unsupported for 1.5 years already...

Anyway, you can try to eval a json structure using json functions https://docs.splunk.com/Documentation/Splunk/8.0.10/SearchReference/JSONFunctions

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...