Splunk Search

Splunk search - is it possible to automatically expand a result property wrap?

gunnist
Explorer

Hi,
In my query:


index="my_local" | sort -Date

I get a list of items, and if I look at one item (and lick "show as raw text") it looks like this:

{"Level":"Info","MessageTemplate":"ApiRequest","RenderedMessage":"ApiRequest","Properties":{"httpMethod":"GET","statusCode":200}, ...}

Since a lot of the properties are wrapped inside "Properties", I always have to expand it manually by clicking the expand icon (with plus sign).

Is there any way to get the search results already expanded (so I don't always have to click "Properties" to manually expand it)?

Many thanks! 🙂

0 Karma
1 Solution

codebuilder
Influencer

You can use mvexpand.

https://docs.splunk.com/Documentation/Splunk/8.2.2/SearchReference/Mvexpand

----
An upvote would be appreciated and Accept Solution if it helps!

View solution in original post

0 Karma

codebuilder
Influencer

You can use mvexpand.

https://docs.splunk.com/Documentation/Splunk/8.2.2/SearchReference/Mvexpand

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

gunnist
Explorer

source=my_local| sort -Date | mvexpand Properties

gives me:

Field 'Properties' does not exist in the data.

 

Am I missing something?

 

0 Karma

codebuilder
Influencer

Does that field exist? And is it a multi-value field?

To verify try something like: source=my_local | table +

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...