Splunk Search

Splunk query to extract json key value

sahuask
Loves-to-Learn

Please help to extract payload data from logs entries and extract the PlatformVersion and PlatformClient values. Need in python code.

Log Entries: 

"tracking~2015~526F3D98","2015:1302",164,1,"2022-02-07 11:10:08.744 INFO [threadPoolTaskExecutorTransformed5 - ?] saving event to log =core-server-event-tracking-api, payload={""PlatformVersion"":""6.34.36 - 4.18.6"",""PlatformClient"":""html""},53
"tracking~2015~526F3D98","2015:130",164423,1,"2022-02-07 11:10:08.744 INFO [threadPoolTaskExecutorTransformed5 - ?] saving event to log =core-server-event-tracking-api, payload={""PlatformVersion"":""6.34.37 - 4.18.7"",""PlatformClient"":""xml""},54

 

Thanks

Labels (1)
Tags (2)
0 Karma

johnhuang
Motivator

Regex:

payload\=\{\"+PlatformVersion[\"\:]*(?<platform_ver>[^\"]*)[\"\,"]*(?<platform_client>[^\"]*)\"

0 Karma

sahuask
Loves-to-Learn

Thanks @johnhuang . 

I am using python and im getting error- Mismatched ']'. 

Can you please provide me the python version of this regex. Thanks

0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @sahuask 

You shall be bit more specific, the SH automatically extract the JSON fields automatically if props.conf having correct settings.

What you mentioned was about python code,  meaning how you going to read the data in python code? 
probably API?

0 Karma

sahuask
Loves-to-Learn

I dont have the control for the configuration setting. the ask is to extract from the log entries as text.

Yes, I need a to use splunk api in python code.

 

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...