I have the following log event but I have not been able to use spath to extract the json key=value pairs.
2013-03-12 10:37:10,205 <tvsquery id=58b6bf4d-948b-416b-8d17-cedcbc1059ec>{
"start" : 1,
"returned" : 0,
"count" : 0
}</tvsquery>
Therefore, I tried to extract the json portion with this regex and then use spath:
|rex field=_raw "
But I having a hard time to make it work.
How can I extract the json portion of the event and then use spath to extract the key=value pairs?
Thanks,
Lp