Splunk Search

How to parse a string with special format into objects or variables?

New Member

Hi there,

I have trying to use spath to try to extract fields inside a string. Currently, the string has this format..



stringField=["fieldOne": "fieldValue", "fieldTwo": "fieldValue", "fieldThree": "fieldValue"]



So, my string inside has some kinda of array with key value pairs. I would to be able to extract those fields and values in a way that I can use their information for my queries. 

I would like to be able to get the value of fieldOne by just calling the fieldOne variable/object to get it's value to perform my desire task/stats and so on.. 

I was trying something like... but no luck!



search... | spath input=stringField 
search... | eval newVariable=spath(_raw,'stringField')
search... | spath
search... | spath path=stringField output=newField



The first option of just using input with the spath command only gave me back the first field inside my string. And it was listed as {} field.

I would really appreciate the help!

Labels (3)
Tags (3)
0 Karma

| eval stringField="{".trim(stringField,"[]")."}"
| spath input=stringField
0 Karma
Get Updates on the Splunk Community!

Introducing Ingest Actions: Filter, Mask, Route, Repeat

WATCH NOW Ingest Actions (IA) is the best new way to easily filter, mask and route your data in Splunk® ...

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...