Splunk Search

How to extract multiple values to same field?

CybSec1
New Member

Hello,

I have logs like : 

samples={'xxxxxxx' : {'111' :{'222' :{'333'}}}}{'yyyyyyy'{'444'}}{'zzzzzzz'}

I need to take all words to one field like ;  my field : 'xxxxxxx','yyyyyyy','zzzzzzz'

Thank you,

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex mode=sed "s/[^[:alpha:]']+//g s/''/','/g s/'',//g"
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @CybSec1 ,

your log seems to be a json file, have you tried with the spath command?

it extract all fields from json files.

For more information see at https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Spath 

then you can use your values in your searches.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...

Application management with Targeted Application Install for Victoria Experience

Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...