Splunk Search

How to extract mutiple value from json

zhenqi
Explorer

Hi,

I want to extract judgments to a fields from "37.0.10.15" and "47.105.153.104",

Is there any way it can do that?

{"data":{"37.0.10.15":{"severity":"medium","judgments":["Scanner","Zombie","Spam"],"tags_classes":[],"basic":{"carrier":"Delis LLC","location":{"country":"The Netherlands","province":"Zuid-Holland","city":"Brielle","lng":"4.16361","lat":"51.90248","country_code":"NL"}},"asn":{},"scene":"","confidence_level":"high","is_malicious":true,"update_time":"2022-06-20 13:00:09"},"47.105.153.104":{"severity":"high","judgments":["Zombie","IDC","Exploit","Spam"],"tags_classes":[{"tags":["Aliyun"],"tags_type":"public_info"}],"basic":{"carrier":"Alibaba Cloud","location":{"country":"China","province":"Shandong","city":"Qingdao City","lng":"120.372878","lat":"36.098733","country_code":"CN"}},"asn":{"rank":2,"info":"CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.,Ltd., CN","number":37963},"scene":"Hosting","confidence_level":"high","is_malicious":true,"update_time":"2022-06-27 21:11:32"}},"response_code":0,"verbose_msg":"OK"}

 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| spath data
| spath input=data
| fields *.judgments{}

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust
| spath data
| spath input=data
| fields *.judgments{}

zhenqi
Explorer

thanks for your help! the result is "37.0.10.15.judgments{}" and "47.105.153.104.judgments{}", what can I do if I want to stats the two judgments to one field?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Not sure what you mean by "stats the two judgments to one field, but you can combine them as a single multi-value field like this

| spath
| spath input=data
| fields *.judgments{}
| foreach *.judgments{}
    [| eval judgments=if(isnull(judgments),'<<FIELD>>',mvappend(judgments,'<<FIELD>>'))]

zhenqi
Explorer

thanks ! I solved the problem by modifying json format,your answer helps me a lot

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...