Splunk Search

How to extract value from search response which has a text plus json?

aliosa
Loves-to-Learn Lots

Hello

I am beginner with Splunk.
I made a query and my search result is like 

 

 

text1 text2 text3 response: {
   "status":"UP",
   "object1":{
      "field1":"name1",
      "status":"UP"
   },
   "object2":{
      "field2":"name2",
      "status":"UP"
   },
   "object3":{
      "object4":{
         "field4":"name4",
         "status":"UP"
      },
      "object5":{
         "field5":"name5",
         "status":"UP"
      },
      "status":"UP"
   },
   "object6":{
      "field6":"name6",
      "status":"UP"
   }
}

 

 

I want to obtain the value for object3.status for a column of table.
How to do this ?
With rex field=_raw or spath ?

Thank you in advance.

Labels (1)
0 Karma

aliosa
Loves-to-Learn Lots

Hello
That json come in search response in multiple lines.
This is not working for me 

rex "response: (?<response>.*)"
because response is "{".

Maybe rex should ignore new line characters (\n) to solve this situation.

and response would be all json {....} 

 

0 Karma

aliosa
Loves-to-Learn Lots

Hello
I use 

| rex "response: (?s)(?<response>.*)"
| spath input=response object3{}.status output=status
| table response, status
and it  works.

Any better idea ?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

I have updated my response.

If it works, this is probably the easiest way to do it. Any other method is likely to be more complex.

0 Karma

aliosa
Loves-to-Learn Lots

ok

thank you.

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

 

| rex "response: (?s)(?<response>.*)"
| spath input=response object3.status output=status
| table status

 

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...