Splunk Search

How to return value from specific key within an object?

bmohammadi
Explorer

Dear Community,

I am new to Splunk so apologies for the newbie question:

Basic Problem

I have a field which holds an Object and I am having difficulties retrieving a value from a specific key within this object.

Purpose

I am running a search and I want to retrieve two datetime values from two separate keys within a field, find the difference between these 2 datetime values and finally return a list of events where the difference is less than a particular value.

I know how to return a table of results based on a simple criteria and can perform datetime manipulations, I just cannot retrieve the actual datetime values needed to make the calculation.

*I can successfully store the whole object to a variable using the eval command but cannot extract the value from it.

Assumptions

The thing I am working with is indeed an Object. I.e. a dictionary style list in the following format

{"key1" : "value" , "key2" : "value" , "key2" : "value"}

I am attempting to extract the value using the eval command

 

Any help would be greatly appreciated.

Kind regards,

Ben

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Use spath - by default spath works on _raw, but you can specify an input field e.g. the field holding your object.

If this isn't enough to go on, perhaps you can provide a bit more detail as to what you are dealing with, e.g. some sample events and which fields you have already extracted from them.

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Use spath - by default spath works on _raw, but you can specify an input field e.g. the field holding your object.

If this isn't enough to go on, perhaps you can provide a bit more detail as to what you are dealing with, e.g. some sample events and which fields you have already extracted from them.

bmohammadi
Explorer

Thank you very much ITWhisperer!

I was able to achieve what I wanted using the following syntax based on you recommendation:

| eval myVariable=spath(fieldName, "Key2")

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...