Splunk Search

Extract Fields with JSON with spath for Data model

longnh26
New Member

Now i very interested with command Spath of Splunk, can auto extract values JSON. But i can't extract it to field in index, sourcetype ?
Example: Raw json in field src_content:

index=web site=demo.com
| spath input=src_content
| table any_property_in_src_content

It will automatic extract fields, very good! But how save this fields ??
- Use Field alias, Calculated fields, Field extractions, Field transformations??
When data have many JSON form, property. If use regex then very hardcore 😞 not good same AUTOMACTIC of spath 😞
- This problem i think same in data model. Please help me solution.

End, i have a question, if a save raw json in field src_content in Datamodel, if query, search, report then i will use spath with src_content in datamodel. Then is its performance much slower?

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...