I have a JSON log entry with key-value pairs within the field component. I'm trying to transform the field into sub-fields using the key-value pairs.
Example:
"msg":{"additionalValues":"{responseTime=137, synapseTag=None, serviceName=switching-integration, uri=com.bigcompany.switching, responseCode=200}", <more fields>,...}
For Splunk, I can pull one field, referenced as "msg.additionalValues". But I can't seem to transform the KVP's within that field into sub-fields. (such as "msg.additionalvalues.responseTime", and msg.additionalvalues.synapseTag, etc )
Any ideas?
Hi @timgren
It looks like the solution in other post might satisfy your requirement. Solved: Re: How to extract fields from child node - Splunk Community
-------------------------------------------------------------
An upvote would be appreciated if it helps!
Well, Not really as that is an inline rex of known fields, not a transformation of subfields which can be a variety of names. But thanks. A transformation at time of ingestion is what I'm after.