Splunk Search

How to iterate over the values of a complex field?

Evgenii
Engager

The event has a field:

 

 

{
...
some_field: {
 key1: value1
 key2: value2
}
...
}

 

 

How to iterate over the values of "some_field" field?

For example I need to get max value.

I need something like this:

... | eval filed_max_value=max(map_values(some_field))

For map_value I get error: Error in 'EvalCommand': The 'map_values' function is unsupported or undefined.

Could you also explain how to use map_keys and map_values functions ?

Labels (2)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

Here's an example that uses foreach to iterate through the keys/values within somefield.

| makeresults
| eval _raw="{\"some_field\": {
\"key1\": 10,
\"key2\": 20,
\"key3\": 5,
\"key4\": 77,
\"key5\": 33,
}
}"
| spath
| foreach some_field.* [
  | eval max=max('<<FIELD>>', max), max_field_key=if('<<FIELD>>'=max, "<<MATCHSTR>>", max_field_key)
]

Note that if there are duplicate values, it will take the last field name as the max_field_key.

Anyway, hope this helps.

 

View solution in original post

Evgenii
Engager

Magic with 

spath | foreach some_field.*

 works.

Thanks a lot!

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Also, those functions you reference are from DSP, not Splunk. 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Here's an example that uses foreach to iterate through the keys/values within somefield.

| makeresults
| eval _raw="{\"some_field\": {
\"key1\": 10,
\"key2\": 20,
\"key3\": 5,
\"key4\": 77,
\"key5\": 33,
}
}"
| spath
| foreach some_field.* [
  | eval max=max('<<FIELD>>', max), max_field_key=if('<<FIELD>>'=max, "<<MATCHSTR>>", max_field_key)
]

Note that if there are duplicate values, it will take the last field name as the max_field_key.

Anyway, hope this helps.

 

Get Updates on the Splunk Community!

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...

Alerting Best Practices: How to Create Good Detectors

At their best, detectors and the alerts they trigger notify teams when applications aren’t performing as ...

Discover Powerful New Features in Splunk Cloud Platform: Enhanced Analytics, ...

Hey Splunky people! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2408. In this ...