Please help with splunk query to get pass and fail count in table format from below jsonarray
| Group | Pass | Fail |
| Group1 | 239 | 6 |
| Group2 | 746 | 14 |
| Group3 | 760 | 10 |
[
{
"Group": 1,
"Pass": 239,
"Fail": 6
},
{
"Group": 2,
"Pass": 746,
"Fail": 14
},
{
"Group": 3,
"Pass": 760,
"Fail": 10
}
]
That's not the prettiest data.
In order to make some sense of this data you have to first parse the outer array
| spath {}
Then you have to split the resulting multivalued field
| mvexpand {}
Now you can parse each of those structures separately
| spath input={}