I have this JSON, and I want extrac the value when the name is "ca-channel
" and value when name is "Ca-Request-Id
" but this data in one row, for example:
channel | requestId
w | 000001707ce0ca4c-58e1e56
At first you just extract the fields from the json format of logs. Then try to filter the portions .
Please follow link to extract the fields :
https://answers.splunk.com/answers/679950/how-to-extract-fields-if-the-event-is-in-json-form.html