Splunk Search

How to extract fields from a json in _raw?

Adisharma
Engager

I have an application which logs data in the following form:

2023-06-30T12:21:08Z DEBUG scalehandler Getting metrics from scaler {"scaledObject.Namespace": "my-namespace", "scaledObject.Name": "my-app", "scaler": "myScaler", "metricName": "http_count_total", "metrics": [], "scalerError": "error getting metrics"}

From the above _raw, I want to extract fields such as scaledObject.Name, scaler and scalerError which I would then use to create an alert.

Could someone help me in creating new fields for the above mentioned json fields using the rex function? 

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

The easiest (although maybe not the most effective) solution would be to use regex to capture the json part and then use spath to extract fields from this part.

<your_search>
| rex "(?<json>\{.*\})"
| spath input=json

 (I'm not sure if the curly braces need escaping or not).

isoutamo
SplunkTrust
SplunkTrust

One comment for this workaround. It extracts those fields as expected, BUT if any event is shorter than 10241 (or whatever you have in limits.conf/kv stanza) character then you have duplicate fields on those events!

Basically you can try to remove duplicates e.g. 

| mvexpand <field name>
| dedup <field name>

Usually this must done one field only. Anyhow this is just workaround until you can fix those values in limits.conf (kv stanza).

See e.g. https://community.splunk.com/t5/Splunk-Search/Why-are-not-all-field-values-are-extracted-for-long-JS... 

0 Karma

dural_yyz
Motivator

https://community.splunk.com/t5/Splunk-Search/How-to-extract-fields-from-JSON-data-in-Splunk/m-p/274...

Look at the answer from javiergn for the solution I would have chosen.

 

Get Updates on the Splunk Community!

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...

Stay Connected: Your Guide to February Tech Talks, Office Hours, and Webinars!

&#x1f48c;Keep the new year’s momentum going with our February lineup of Community Office Hours, Tech Talks, ...