Splunk Search

Use quoted parameter in request

MaximKorobov
New Member

I have quoted parameters in log files, which are processed by Splunk:

"Version":"21"

How to extract that parameter to use in requests like this:

Version = "21" OR ...

Please note that it's no chance to modify current Splunk's config files.

(original question: stackoverflow #18897765)

Tags (2)
0 Karma
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

You can try this:

your_search | extract kvdelim=":" | search Version="21"

This will pull the Key Value pairs that are delimited by a colon ":".

View solution in original post

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

You can try this:

your_search | extract kvdelim=":" | search Version="21"

This will pull the Key Value pairs that are delimited by a colon ":".

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

|extract kvdelim=":" pairdelim=","

0 Karma

MaximKorobov
New Member

I tryed it with no luck. Example: "Model":"Lenovo K900_ROW","Android":"4.2.1","Date":"Mon Sep 30 23:58:27 GMT+03:00 2013","Build":"RC11","LastActivity":"ru.TextActivity","Version":"21""StackTrace":"java.lang.RuntimeException"... wasn't found.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...