Splunk Search

Multivalue field extraction from nested field

b17gunnr
Path Finder

 

Hello folks,

I have a series of event results which take the format as shown below:

   appDisplayName: foo
   appId: foo0
   appliedConditionalAccessPolicies: [ [-]
     { [-]
       displayName: All Users Require MFA All Apps
       enforcedGrantControls: [ [+]
       ]
       enforcedSessionControls: [ [+]
       ]
       id: foo1
       result: success
     }
     { [-]
       displayName: macOS Conditional Access Policy
       enforcedGrantControls: [ [+]
       ]
       enforcedSessionControls: [ [+]
       ]
       id: foo2
       result: success
     }
     { [-]
       displayName: Global-Restrict
       enforcedGrantControls: [ [+]
       ]
       enforcedSessionControls: [ [+]
       ]
       id: foo3
       result: notApplied
     }
     { [-]
       displayName: All_user_risk_policy
       enforcedGrantControls: [ [+]
       ]
       enforcedSessionControls: [ [+]
       ]
       id: foo4
       result: notApplied

Is there a way to cycle through the specific event to extract and maintain the correlation of field:value and then repeat for one or more event blocks? Effectively it would look like this:

displayName: All Users Require MFA All Apps - id: foo1 - result: success

displayName: macOS Conditional Access Policy - id: foo2 - result: success

displayName: Global-Restrict - id: foo3 - result: notApplied

displayName: All_user_risk_policy - id: foo4 - result: notApplied

Thank you to all.

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| spath appliedConditionalAccessPolicies{} output=appliedConditionalAccessPolicies
| mvexpand appliedConditionalAccessPolicies
| spath input=appliedConditionalAccessPolicies

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust
| spath appliedConditionalAccessPolicies{} output=appliedConditionalAccessPolicies
| mvexpand appliedConditionalAccessPolicies
| spath input=appliedConditionalAccessPolicies

b17gunnr
Path Finder

This was it. Thank you for the assist.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Extract appliedConditionalAccessPolicies as a whole, expand the multivalued field, then extract each row separately.

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...