Splunk Search

How do I extract fields from a json object (serialized) and put it back to splunk index?

arungeorge09
Path Finder

Sample data:

<167>1 2014-11-15T16:45:44.542-07:00 host.name.com neat 11151 gcm [meta@28281 sequenceId="43096" sysUpTime="858744854"][analytics@28281 event="pushGcm" platform="GCM" outcome="0" errorCode="0" errorDesc="Push to apns success" errorContext="TCP-SSL" operation="PUSH_GCM" opTime="46" startTime="1416095144542" appId="appId" deviceToken="token" args="{\"time\":\"1416095144194\",\"batch\":\"26966\",\"tms_id\":\"tmsid\",\"src\":\"src\"}" txId="907472412"] 

I want to extract the args and put it back in its appropriate fields . I know I can use Field Extractions and Field transformations but not working.

Field Transformation
Name:NEAT_BATCH

Rex: batch\\\\\":\\\\\"(?.*?)\\\\\",

Field Extraction
Name:NEAT_BATCH

0 Karma
1 Solution

tom_frotscher
Builder

Hi,
try it with this regular expression for the batch field:

\\\"batch\\":\\"(?<batch>\d+)\\"

Greetings

Tom

View solution in original post

tom_frotscher
Builder

Hi,
try it with this regular expression for the batch field:

\\\"batch\\":\\"(?<batch>\d+)\\"

Greetings

Tom

arungeorge09
Path Finder

Worked. Thanks Tom. Why does not it work with my regexp . Can you explain

0 Karma

tom_frotscher
Builder

Your regex didn't match. there are way to much "\" symbols in your regex and i think also your group definition "(?.*?)" is syntactically wrong.

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...