Splunk Search

How do I show nested field in one box in a table?

nikosattlermhp
Engager

How can I get the nested JSON in this field called "Message" (see below) with the nested fields (here currentMessage) as one String which is: Message": [3, "83052143", {"currentTime": "2018-11-15T14:13:16.967+0000"}]. Goal is to show this String in a table in one box. (the whole string in one box.) The content and the number of fields inside the message field is variable!

So rex for the nested fields didn't work for me.

alt text

Thank you in advance.

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...