Splunk Search

Splunk search help: formatting a field

New Member

Can somebody help me with a Splunk query to format the below MESSAGE field value

  • MESSAGE=ABC-STATUS-COUNT={\"false\":1,\"true\":1}\n

as something like below

  • MESSAGE=ABC-STATUS-COUNT-{false:1,true:1}
0 Karma


You can do like this (runanywhere search, replace line1 with your search)

| gentimes start=-1 | eval MESSAGE="ABC-STATUS-COUNT={\\\"false\\\":1,\\\"true\\\":1}\\n" 
| rex field=MESSAGE mode=sed "s/\\\[\"\w]//g"