Splunk Search

array

vinod0313
Explorer

Hello

I have log like below

FEATURES_USING=[tokenValidatorInfo=false, requestValidationRequired=false, requestPayloadValidationRequired=false, responsePayloadValidationRequired=false, aopUsed=false, tibcoCommunicatorUsed=false, secretsSecured=false]


I want result should be like below(should splitin 2 columns)

Column1                                                                                                   column2

tokenValidatorInfo                                                                                  false

requestValidationRequired                                                                false

requestPayloadValidationRequired                                                false

-----                                                                                                               ---

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Hi @vinod0313 

An additional requirement to your previous question! here  and not a great leap to this:

| rex field=_raw "FEATURES_USING=\[(?<feature>.*)\]" 
| makemv delim=", " feature 
| mvexpand feature 
| rex field=feature "(?<Column1>[^=]*)=(?<column2>.*)"
| fields Column1,column2

 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

See if this helps.

| makeresults | eval _raw="FEATURES_USING=[tokenValidatorInfo=false, requestValidationRequired=false, requestPayloadValidationRequired=false, responsePayloadValidationRequired=false, aopUsed=false, tibcoCommunicatorUsed=false, secretsSecured=false]" 
```Above is just to create test data```
| extract pairdelim="[,]", kvdelim="="
| fields - FEATURES_USING _raw _time _kv
| transpose 0 column_name="column1"
| rename "row 1" as column2
---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Thank you for not using "splunk" as the subject of this posting.  It would be better still to use more than a single word.  For example: "How to parse an array?"

What have to tried so far to solve this problem?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...