Splunk Search

Please help with splunk query to get pass and fail count from jsonarray

Thulasiraman
Explorer

Please help with splunk query to get pass and fail count in table format from below jsonarray

| Group   | Pass | Fail |
| Group1 | 239    | 6     |
| Group2 | 746    | 14    |
| Group3 | 760    | 10     |


[
{
"Group": 1,
"Pass": 239,
"Fail": 6
},
{
"Group": 2,
"Pass": 746,
"Fail": 14
},
{
"Group": 3,
"Pass": 760,
"Fail": 10
}
]

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

That's not the prettiest data.

In order to make some sense of this data you have to first parse the outer array

| spath {}

Then you have to split the resulting multivalued field

| mvexpand {}

Now you can parse each of those structures separately

| spath input={}

 

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...