Splunk Search

array

vinod0313
Explorer

Hello

I have log like below

FEATURES_USING=[tokenValidatorInfo=false, requestValidationRequired=false, requestPayloadValidationRequired=false, responsePayloadValidationRequired=false, aopUsed=false, tibcoCommunicatorUsed=false, secretsSecured=false]


I want result should be like below(should splitin 2 columns)

Column1                                                                                                   column2

tokenValidatorInfo                                                                                  false

requestValidationRequired                                                                false

requestPayloadValidationRequired                                                false

-----                                                                                                               ---

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Hi @vinod0313 

An additional requirement to your previous question! here  and not a great leap to this:

| rex field=_raw "FEATURES_USING=\[(?<feature>.*)\]" 
| makemv delim=", " feature 
| mvexpand feature 
| rex field=feature "(?<Column1>[^=]*)=(?<column2>.*)"
| fields Column1,column2

 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

See if this helps.

| makeresults | eval _raw="FEATURES_USING=[tokenValidatorInfo=false, requestValidationRequired=false, requestPayloadValidationRequired=false, responsePayloadValidationRequired=false, aopUsed=false, tibcoCommunicatorUsed=false, secretsSecured=false]" 
```Above is just to create test data```
| extract pairdelim="[,]", kvdelim="="
| fields - FEATURES_USING _raw _time _kv
| transpose 0 column_name="column1"
| rename "row 1" as column2
---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Thank you for not using "splunk" as the subject of this posting.  It would be better still to use more than a single word.  For example: "How to parse an array?"

What have to tried so far to solve this problem?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...