Splunk Search

array

vinod0313
Explorer

Hello

I have log like below

FEATURES_USING=[tokenValidatorInfo=false, requestValidationRequired=false, requestPayloadValidationRequired=false, responsePayloadValidationRequired=false, aopUsed=false, tibcoCommunicatorUsed=false, secretsSecured=false]


I want result should be like below(should splitin 2 columns)

Column1                                                                                                   column2

tokenValidatorInfo                                                                                  false

requestValidationRequired                                                                false

requestPayloadValidationRequired                                                false

-----                                                                                                               ---

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Hi @vinod0313 

An additional requirement to your previous question! here  and not a great leap to this:

| rex field=_raw "FEATURES_USING=\[(?<feature>.*)\]" 
| makemv delim=", " feature 
| mvexpand feature 
| rex field=feature "(?<Column1>[^=]*)=(?<column2>.*)"
| fields Column1,column2

 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

See if this helps.

| makeresults | eval _raw="FEATURES_USING=[tokenValidatorInfo=false, requestValidationRequired=false, requestPayloadValidationRequired=false, responsePayloadValidationRequired=false, aopUsed=false, tibcoCommunicatorUsed=false, secretsSecured=false]" 
```Above is just to create test data```
| extract pairdelim="[,]", kvdelim="="
| fields - FEATURES_USING _raw _time _kv
| transpose 0 column_name="column1"
| rename "row 1" as column2
---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Thank you for not using "splunk" as the subject of this posting.  It would be better still to use more than a single word.  For example: "How to parse an array?"

What have to tried so far to solve this problem?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...